|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover three different methods of function hooking for Mac OSX and Linux. The talk will begin by describing useful bits of Intel64 assembly followed up with 3 different binary rewriting techniques to hook a range of different functions, including some inlined functions, too. We'll finish up with a demo of two nice things that these techniques make possible (a memory profiler and a function call tracer), and one slightly more e..
|
|
The available pool of IPv4 address space has reached a critical level. With about 7% of the IPv4 free pool remaining, organizations should already be taking steps to prepare for IPv6. There is only about a year before IPv4 is fully depleted, so it is vital that all companies adopt IPv6, the next generation of Internet Protocol, now to avoid growth and scaling issues down the road. While IPv6 will help lead the development and deploymen....
|
|
This talk will cover three different methods of function hooking for Mac OSX and Linux. The talk will begin by describing useful bits of Intel64 assembly followed up with 3 different binary rewriting techniques to hook a range of different functions, including some inlined functions, too. We'll finish up with a demo of two nice things that these techniques make possible (a memory profiler and a function call tracer), and one slightly more e..
|
|
The available pool of IPv4 address space has reached a critical level. With about 7% of the IPv4 free pool remaining, organizations should already be taking steps to prepare for IPv6. There is only about a year before IPv4 is fully depleted, so it is vital that all companies adopt IPv6, the next generation of Internet Protocol, now to avoid growth and scaling issues down the road. While IPv6 will help lead the development and deploymen....
|
|
This talk will cover three different methods of function hooking for Mac OSX and Linux. The talk will begin by describing useful bits of Intel64 assembly followed up with 3 different binary rewriting techniques to hook a range of different functions, including some inlined functions, too. We'll finish up with a demo of two nice things that these techniques make possible (a memory profiler and a function call tracer), and one slightly more e..
|
|
The available pool of IPv4 address space has reached a critical level. With about 7% of the IPv4 free pool remaining, organizations should already be taking steps to prepare for IPv6. There is only about a year before IPv4 is fully depleted, so it is vital that all companies adopt IPv6, the next generation of Internet Protocol, now to avoid growth and scaling issues down the road. While IPv6 will help lead the development and deploymen....
|
|
John McNabb - Cyberterrorism and the Security of the National Drinking Water Infrastructure
-
www.defcon.org
-
15 years ago
-
eng
The national drinking water infrastructure is vitally important to protection of public health and safety and also supports business, industry, and the national economy. While steps have been taken since 9/11 to identify and mitigate vulnerabilities in the drinking water infrastructure, serious vulnerabilities remain. In this talk, the presenter will discuss and review the challenges of physical and cyber security for the national public dr....
|
|
John McNabb - Cyberterrorism and the Security of the National Drinking Water Infrastructure
-
www.defcon.org
-
15 years ago
-
eng
The national drinking water infrastructure is vitally important to protection of public health and safety and also supports business, industry, and the national economy. While steps have been taken since 9/11 to identify and mitigate vulnerabilities in the drinking water infrastructure, serious vulnerabilities remain. In this talk, the presenter will discuss and review the challenges of physical and cyber security for the national public dr....
|
|
John McNabb - Cyberterrorism and the Security of the National Drinking Water Infrastructure
-
www.defcon.org
-
15 years ago
-
eng
The national drinking water infrastructure is vitally important to protection of public health and safety and also supports business, industry, and the national economy. While steps have been taken since 9/11 to identify and mitigate vulnerabilities in the drinking water infrastructure, serious vulnerabilities remain. In this talk, the presenter will discuss and review the challenges of physical and cyber security for the national public dr....
|
|
What do you do when you get inside of a .Net program? This presentation will demonstrate taking full advantage of the .Net world from the inside. Once inside of a program don't just put in a key-logger, remold it! I will presentation a how to infiltrate, evaluate, subvert, combine, and edit .Net applications at Runtime. The techniques demonstrated will focus on the modification of core logic in protected .Net programs. This will make a....
|
|
What do you do when you get inside of a .Net program? This presentation will demonstrate taking full advantage of the .Net world from the inside. Once inside of a program don't just put in a key-logger, remold it! I will presentation a how to infiltrate, evaluate, subvert, combine, and edit .Net applications at Runtime. The techniques demonstrated will focus on the modification of core logic in protected .Net programs. This will make a....
|
|
What do you do when you get inside of a .Net program? This presentation will demonstrate taking full advantage of the .Net world from the inside. Once inside of a program don't just put in a key-logger, remold it! I will presentation a how to infiltrate, evaluate, subvert, combine, and edit .Net applications at Runtime. The techniques demonstrated will focus on the modification of core logic in protected .Net programs. This will make a....
|
|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Josh Pyorre & Chris McKenney - Build Your Own Security Operations Center for Little or No Money
-
www.defcon.org
-
15 years ago
-
eng
In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....
|
|
Joshua Marpet - Facial Recognition: Facts, Fiction; and Fcsk-Ups!
-
www.defcon.org
-
15 years ago
-
eng
Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....
|
|
Josh Pyorre & Chris McKenney - Build Your Own Security Operations Center for Little or No Money
-
www.defcon.org
-
15 years ago
-
eng
In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....
|
|
Joshua Marpet - Facial Recognition: Facts, Fiction; and Fcsk-Ups!
-
www.defcon.org
-
15 years ago
-
eng
Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....
|