|
Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....
|
|
This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..
|
|
Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....
|
|
This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..
|
|
Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....
|
|
This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..
|
|
Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..
|
|
Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..
|
|
Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..
|
|
With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..
|
|
ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....
|
|
With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..
|
|
ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....
|
|
With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..
|
|
ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....
|
|
WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....
|
|
WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....
|
|
WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....
|
|
metr0 - Securing MMOs: A Security Professional's View from the Inside
-
www.defcon.org
-
15 years ago
-
eng
Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..
|
|
This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..
|
|
metr0 - Securing MMOs: A Security Professional's View from the Inside
-
www.defcon.org
-
15 years ago
-
eng
Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..
|
|
This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..
|
|
metr0 - Securing MMOs: A Security Professional's View from the Inside
-
www.defcon.org
-
15 years ago
-
eng
Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..
|
|
This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..
|
|
SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....
|
|
SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....
|
|
SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....
|
|
Michael Weigand, Renderman & Mike Kershaw - Build your own UAV 2.0 - Wireless Mayhem from the Heavens!
-
www.defcon.org
-
15 years ago
-
eng
Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....
|
|
A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..
|
|
Michael Weigand, Renderman & Mike Kershaw - Build your own UAV 2.0 - Wireless Mayhem from the Heavens!
-
www.defcon.org
-
15 years ago
-
eng
Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....
|
|
A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..
|
|
Michael Weigand, Renderman & Mike Kershaw - Build your own UAV 2.0 - Wireless Mayhem from the Heavens!
-
www.defcon.org
-
15 years ago
-
eng
Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....
|
|
A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..
|
|
Mike Metzger - Letting the Air Out of Tire Pressure Monitoring Systems
-
www.defcon.org
-
15 years ago
-
eng
Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..
|
|
Monta Elkins - Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device - URFUKED
-
www.defcon.org
-
15 years ago
-
eng
If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..
|
|
Mike Metzger - Letting the Air Out of Tire Pressure Monitoring Systems
-
www.defcon.org
-
15 years ago
-
eng
Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..
|
|
Monta Elkins - Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device - URFUKED
-
www.defcon.org
-
15 years ago
-
eng
If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..
|
|
Mike Metzger - Letting the Air Out of Tire Pressure Monitoring Systems
-
www.defcon.org
-
15 years ago
-
eng
Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..
|
|
Monta Elkins - Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device - URFUKED
-
www.defcon.org
-
15 years ago
-
eng
If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..
|
|
Moxie Marlinspike - Changing Threats To Privacy: From TIA to Google
-
www.defcon.org
-
15 years ago
-
eng
A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....
|
|
Moxie Marlinspike - Changing Threats To Privacy: From TIA to Google
-
www.defcon.org
-
15 years ago
-
eng
A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....
|
|
Moxie Marlinspike - Changing Threats To Privacy: From TIA to Google
-
www.defcon.org
-
15 years ago
-
eng
A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....
|
|
Nathan Hamiel & Marcin Wielgoszewski - Constricting the Web: Offensive Python for Web Hackers
-
www.defcon.org
-
15 years ago
-
eng
It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python p....
|
|
Nguyen Anh Quynh - Operating System Fingerprinting for Virtual Machines
-
www.defcon.org
-
15 years ago
-
eng
Operating System fingerprinting (OSF) is important to help on deciding security policy enforced on protected Virtual Machine (VM). Unfortunately, current OSF techniques suffer many problems, such as: they fail badly against modern Operating Systems (OS), they are slow, and only support limited OS-es and hypervisors. This paper analyzes the drawbacks of current OSF approaches against VM in the cloud, then introduces a novel method, name....
|