|
Angus Blitter - Fear and Loathing in Cyberspace: The art and science of enemy profiling
-
defcon.org
-
16 years ago
-
eng
Quickly identifying your opponent, in any conflict, can mean the difference between success and failure. Knowing their capabilities, resources and limitations can provide the tactical advantage. The lack of this type of decision support is a serious deficiency in most information warrior's arsenals. Relying on single source intelligence is pure folly. Charlatans and carpetbaggers are salivating at the millions in government and corporate d....
|
|
Angus Blitter - Fear and Loathing in Cyberspace: The art and science of enemy profiling
-
defcon.org
-
16 years ago
-
eng
Quickly identifying your opponent, in any conflict, can mean the difference between success and failure. Knowing their capabilities, resources and limitations can provide the tactical advantage. The lack of this type of decision support is a serious deficiency in most information warrior's arsenals. Relying on single source intelligence is pure folly. Charlatans and carpetbaggers are salivating at the millions in government and corporate d....
|
|
Angus Blitter - Fear and Loathing in Cyberspace: The art and science of enemy profiling
-
defcon.org
-
16 years ago
-
eng
Quickly identifying your opponent, in any conflict, can mean the difference between success and failure. Knowing their capabilities, resources and limitations can provide the tactical advantage. The lack of this type of decision support is a serious deficiency in most information warrior's arsenals. Relying on single source intelligence is pure folly. Charlatans and carpetbaggers are salivating at the millions in government and corporate d....
|
This session will address the techniques used to investigate network-based intrusions, especially those originating from the public Internet. Emphasis will be on techniques that provide an acceptable chain of evidence for use by law enforcement or in anticipation of civil litigation. We will cover back-tracing, forensic tools, end-to-end tracing and evidence collection and preservation as well as the forensic use of RMON2-based tools for ....
|
This session will address the techniques used to investigate network-based intrusions, especially those originating from the public Internet. Emphasis will be on techniques that provide an acceptable chain of evidence for use by law enforcement or in anticipation of civil litigation. We will cover back-tracing, forensic tools, end-to-end tracing and evidence collection and preservation as well as the forensic use of RMON2-based tools for ....
|
This session will address the techniques used to investigate network-based intrusions, especially those originating from the public Internet. Emphasis will be on techniques that provide an acceptable chain of evidence for use by law enforcement or in anticipation of civil litigation. We will cover back-tracing, forensic tools, end-to-end tracing and evidence collection and preservation as well as the forensic use of RMON2-based tools for ....
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
DEF CON 7.0 was held July 9-11th, 1999, in Las Vegas Nevada USA Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the presentations wh..
|
|
Available on the new website: stainless.sf.net There's a whole bunch of new stuff in v0.4 that I don't have time to talk about. So check out the website to see the new HD trailer.
|
Recent Activity Mar. 11, 2019GitHub ( web-flow ) Update README.md Apr. 14, 2015Jesse Donat ( donatj ) Correct year and formatting Create LICENSE.md Jan. 7, 2014Merge pull request #9 from bitdeli-chef/master Add a Bitdeli Badge to README Bitdeli Chef ( bitdeli-chef ) Add a Bitdeli badge to README Jul. 15, 2013Jesse Donat ( donatj ) Better constant May. 16, 2013Cache class made to serialize Apr. 26, 2013Corrections to the Gith....
|
Recent Activity Mar. 11, 2019GitHub ( web-flow ) Update README.md Apr. 14, 2015Jesse Donat ( donatj ) Correct year and formatting Create LICENSE.md Jan. 7, 2014Merge pull request #9 from bitdeli-chef/master Add a Bitdeli Badge to README Bitdeli Chef ( bitdeli-chef ) Add a Bitdeli badge to README Jul. 15, 2013Jesse Donat ( donatj ) Better constant May. 16, 2013Cache class made to serialize Apr. 26, 2013Corrections to the Gith....
|
|
America’s Forgotten Problem by Samuel Solomon / ASSOCIATE NEWS EDITOR 12.03.09 – 05:00 am American infrastructure is failing.
|
|
For å bli bedre må man trene. For å bli bedre med avanserte ting, må man forstå de grunnleggende tingene bra. For å vite hvorfor man bruker avanserte verktøy, må man prøve å jobbe uten dem. Derfor har jeg de siste ukene trent mange ganger på å lage en veldig enkel webapplikasjon i Java. For hele applikasjonen har jeg startet med å skrive testene før koden som implementerer funksjonaliteten. Dersom du vil prøve deg på samme øvelse, inneholde..
|
|
Luke Jennings:One Token to Rule Them All: Post-Exploitation Fun in Windows Environments
-
www.defcon.org
-
16 years ago
-
eng
The defense techniques employed by large software manufacturers are getting better. This is particularly true of Microsoft who have improved the security of the software they make tremendously since their Trustworthy Computing initiative. Gone are the days of being able to penetrate any Microsoft system by firing off the RPC-DCOM exploit. The consequence of this is that post-exploitation has become increasingly important in order to "squeez....
|
|
Luke Jennings:One Token to Rule Them All: Post-Exploitation Fun in Windows Environments
-
www.defcon.org
-
16 years ago
-
eng
The defense techniques employed by large software manufacturers are getting better. This is particularly true of Microsoft who have improved the security of the software they make tremendously since their Trustworthy Computing initiative. Gone are the days of being able to penetrate any Microsoft system by firing off the RPC-DCOM exploit. The consequence of this is that post-exploitation has become increasingly important in order to "squeez....
|
|
Spidering, in its simplest form is the act of transferring data from one database to another. Spidering requires the use of Regular Expressions, the cURL library (if POST data or cookies are used), and the cron libraries (if we need to download information with a schedule).
|
|
En kollega spurte i dag om mine topp tips når det gjelder databaserefactorings. Her var mitt svar: Ha en organisert struktur med at man gjennomfører navngitte migreringer (a la Ruby-on-Rails sine migrations eller dbdeploy). Typisk er det vanlig og velfungerende å navngi scripts med løpenummer (001, 002, …) eller timestamp (20091124071300, …) og ha en tabell i databasen som holder styr på hva som har blitt kjørt Bruk views og materialiserte ..
|
|
Yes, you can now view the last five games you played as a spectator! All I did was save each network packet that's sent out into a big list, then use Python's pickle module to serialize the list to a file. Each packet has a timestamp, so I just read the packets back in order, checking the timestamps to make sure it reads the packets back at the right speed. Fast forwarding is not implemented, but it would be pretty easy. Rewinding/seeking w..
|
|
An estimated $42,500 in laptop computers was stolen from the Haley Center between Nov. 6 and Nov. 9. Twenty-five laptops were stolen.
|
|
Pedro hkm Joaquin - Attacks Against 2wire Residential Gateway Routers - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacks Against 2wire Residential Gateways Pedro "hkm" Joaquin Some time ago there was a vulnerability in 2wire residential routers that allowed DNS Poisoning via Cross Site Request Forgery, this was widely exploited in Mexico where this router is most commonly used. The patch actually contained an Authentication Bypass vulnerability that made things worse, and now, after the patch got patched, there are still many public unpatc....
|
|
Brandon Dixon - Attacking SMS its no longer your BFF - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacking SMS. It's No Longer Your BFF Brandon Dixon Information Systems Security Engineer at G2, Inc. It's the year 2009 and spam mail is still taking up a huge percentage of all email sent everyday over the Internet. Could you imagine that same messaging spam making a detour through your favorite cellular provider gateway and right to your SMS inbox? Mobile spam has not reached the same popularity as email spam, but what if it was ....
|
|
Antony Rucci - Protecting Against and Investigating Insider Threats A Methodical Multi-Pronged Approach to Protecting Your Organization - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Protecting Against and Investigating Insider Threats (A methodical, multi-pronged approach to protecting your organization) Antonio "Tony" Rucci Program Director, Technical Intelligence and Security Programs, Oak Ridge National Laboratory This presentation will focus on indicators of insider threats and how to detect them. I’ll primarily focus on specific hiring practices to minimize risk to your organization. We’ll take a deep dive ....
|
|
Failure Adam Savage Co-Host, MythBusters A meditation on how I've screwed things up, lost friends and clients, and learned about myself in the process. Adam Savage has spent his life gathering skills that allow him to take what's in his brain, and make it real. He's built everything from ancient Buddhas to futuristic weapons, from spaceships to dancing vegetables, from fine art sculptures to animated chocolate -- and just about anyt....
|
|
Hacking the Smart Grid Tony Flick The city of Miami and several commercial partners plan to rollout a "smart grid" citywide electrical infrastructure by the year 2011. This rollout proceeds on the heels of news that foreign agents have infiltrated our existing electrical infrastructure and that recent penetration tests have uncovered numerous vulnerabilities in the proposed technologies. Simultaneously, the National Institute for Sta....
|
|
Pedro hkm Joaquin - Attacks Against 2wire Residential Gateway Routers - Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacks Against 2wire Residential Gateways Pedro "hkm" Joaquin Some time ago there was a vulnerability in 2wire residential routers that allowed DNS Poisoning via Cross Site Request Forgery, this was widely exploited in Mexico where this router is most commonly used. The patch actually contained an Authentication Bypass vulnerability that made things worse, and now, after the patch got patched, there are still many public unpatc....
|
|
Nicholas Percoco and Jibran Ilyas - Malware Freak Show - Slides
-
www.defcon.org
-
16 years ago
-
eng
Malware Freak Show Nicholas J. Percoco Vice President of SpiderLabs, Trustwave Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner work....
|
|
Matt Richard and Steven Adair - 0-day gh0stnet and the Inside Story of the Adobe JBIG2 Vulnerability - Slides
-
www.defcon.org
-
16 years ago
-
eng
0-day, gh0stnet and the inside story of the Adobe JBIG2 vulnerability Matt Richard Malicious Code Researcher, Raytheon Steven Adair Researcher, Shadowserver This talk is the story of 0-day PDF attacks, the now famous gh0stnet ring and the disclosure debacle of the Adobe JBIG2 vulnerability in January and February 2009. This is the story of international cyber-espionage using 0-days and the fierce debate over how to defend networks ....
|
|
Joey Calca and Ryan Anguiano - Hadoop Apaches Open Source Implementation of Googles MapReduce Framework- Slides
-
www.defcon.org
-
16 years ago
-
eng
Hadoop: Apache's Open Source Implementation of Google's MapReduce Framework Joey Calca Hacked Existence Team Ryan Anguiano Hacked Existence Team This presentation will begin with a brief overview of Google's Map/Reduce Framework. Map/Reduce is built to analyze extremely large datasets. We will first look at what a Mapper and Reducer are, the inputs they take and the outputs they generate. From there, we will look at the open source....
|
|
Doppelganger: The Web's Evil Twin Edward Zaborowski Senior Security Engineer, Apptis Users and administrators alike surf the web assuming that, for the most part, what they are looking at is what the website served to their browser; however, an attacker can deploy a malicious proxy, altering responses and requests, as well as potentially stealing sensitive data, all without a user being aware. In this presentation I will discuss....
|
|
Danny Quist and Lorie Liebrock - Reverse Engineering by Crayon - Slides
-
www.defcon.org
-
16 years ago
-
eng
Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization Danny Quist CEO, Offensive Computing Lorie M. Liebrock New Mexico Tech Computer Science Department Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques....
|
|
Something about Network Security Dan Kaminsky IOActive Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and de..
|
|
Antony Rucci - Protecting Against and Investigating Insider Threats A Methodical Multi-Pronged Approach to Protecting Your Organization - Slides
-
www.defcon.org
-
16 years ago
-
eng
Protecting Against and Investigating Insider Threats (A methodical, multi-pronged approach to protecting your organization) Antonio "Tony" Rucci Program Director, Technical Intelligence and Security Programs, Oak Ridge National Laboratory This presentation will focus on indicators of insider threats and how to detect them. I’ll primarily focus on specific hiring practices to minimize risk to your organization. We’ll take a deep dive ....
|
|
Antione Gademer and Corentin Cheron - Low cost Spying Quadrotor for Global Security Applications - Slides
-
www.defcon.org
-
16 years ago
-
eng
A Low Cost Spying Quadrotor for Global security Applications Using Hacked Commercial Digital Camera Antoine Gademer Corentin Chéron Accessing centimetric georeferenced images is crucial for local military or civil intelligence, reconnaissance and surveillance applications. When classical satellite or aerial imagery is not available the Unmanned Aircraft Systems (UAS) are often a very interesting solution. But having an operational ....
|
|
Failure Adam Savage Co-Host, MythBusters A meditation on how I've screwed things up, lost friends and clients, and learned about myself in the process. Adam Savage has spent his life gathering skills that allow him to take what's in his brain, and make it real. He's built everything from ancient Buddhas to futuristic weapons, from spaceships to dancing vegetables, from fine art sculptures to animated chocolate -- and just about anyt....
|
|
There’s another interesting thread going on in Oracle-L, about understanding logical IOs and drilling down into their reasons. Of course sometimes (or rather usually) the excessive logical IOs come from a bad execution plan (when a nested loop loops over lots of datablocks again and again or a wrong index is used for driving a query etc), but sometimes the excessive LIOs are caused by some internal issues, like space management etc. A c....
|
|
There’s another interesting thread going on in Oracle-L, about understanding logical IOs and drilling down into their reasons. Of course sometimes (or rather usually) the excessive logical IOs come from a bad execution plan (when a nested loop loops over lots of datablocks again and again or a wrong index is used for driving a query etc), but sometimes the excessive LIOs are caused by some internal issues, like space management etc. A c....
|