|
Dark Tangent and Defcon Staff Closing Ceremonies The Conference is wrapped up, Closing speech by The Dark Tangent, Thank you speeches are given and Contest results are announced.
|
|
Dark Tangent and Defcon Staff Closing Ceremonies The Conference is wrapped up, Closing speech by The Dark Tangent, Thank you speeches are given and Contest results are announced.
|
|
Something about Network Security Dan Kaminsky IOActive Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and de..
|
|
Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....
|
|
Danny Quist and Lorie Liebrock - Reverse Engineering by Crayon
-
www.defcon.org
-
16 years ago
-
eng
Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization Danny Quist CEO, Offensive Computing Lorie M. Liebrock New Mexico Tech Computer Science Department Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques....
|
|
Dan Kaminsky - Something about Network Security -Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Something about Network Security Dan Kaminsky IOActive Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and de..
|
|
Daniel Raygoza - Automated Malware Similarity Analysis - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....
|
|
Danny Quist and Lorie Liebrock - Reverse Engineering by Crayon -Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization Danny Quist CEO, Offensive Computing Lorie M. Liebrock New Mexico Tech Computer Science Department Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques....
|
|
Daniel Raygoza - Automated Malware Similarity Analysis - Slides
-
www.defcon.org
-
16 years ago
-
eng
Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....
|
|
Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.
|
|
Da Beave and JFalcon - AAPL Automated Analog Telephone Logging
-
www.defcon.org
-
16 years ago
-
eng
AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....
|
|
Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.
|
|
Da Beave and JFalcon - AAPL Automated Analog Telephone Logging - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....
|
|
Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.
|
|
Da Beave and JFalcon - AAPL Automated Analog Telephone Logging - Slides
-
www.defcon.org
-
16 years ago
-
eng
AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....
|
|
RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..
|
|
Christopher Mooney and James Luedke - Subverting the World of Warcraft API
-
www.defcon.org
-
16 years ago
-
eng
Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....
|
|
Christopher Soghoian - Manipulation and Abuse of the Consumer Credit Reporting Agencies
-
www.defcon.org
-
16 years ago
-
eng
Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....
|
|
Cody Pollet and George Louthan - Hack like the Movie Stars A Big Screen Multi Touch Network Monitor
-
www.defcon.org
-
16 years ago
-
eng
Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....
|
|
RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..
|
|
Christopher Mooney and James Luedke - Subverting the World of Warcraft API - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....
|
|
Christopher Soghoian - Manipulation and Abuse of the Consumer Credit Reporting Agencies - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....
|
|
Cody Pollet and George Louthan - Hack like the Movie Stars A Big Screen Multi Touch Network Monitor - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....
|
|
RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..
|
|
Christopher Mooney and James Luedke - Subverting the World of Warcraft API - Slides
-
www.defcon.org
-
16 years ago
-
eng
Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....
|
|
Christopher Soghoian - Manipulation and Abuse of the Consumer Credit Reporting Agencies - Slides
-
www.defcon.org
-
16 years ago
-
eng
Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....
|
|
Cody Pollet and George Louthan - Hack like the Movie Stars A Big Screen Multi Touch Network Monitor - Slides
-
www.defcon.org
-
16 years ago
-
eng
Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....
|
|
Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..
|
|
Proxy Prank-o-Matic Charlie Vedaa Founder @ PacketProtector.org "Anonymous secondary speaker" The Upside-Down-Ternet was just the beginning. What else can you do with a proxy server and a mischievous mind? We'll show you how to send your victims back in time (fun with archive.org), to the all-porn Internet (is there any other kind?), or to the Tourette-net (Cartman runs the Internets)! Via browser settings or port forwarding, using..
|
|
Chema Alonso and Jose Palazon - Tactical Fingerprinting Using Metadata Hidden Info and Lost Data
-
www.defcon.org
-
16 years ago
-
eng
Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data Chema Alonso MVP Enterprise Security, CTO Inform·tica64 Jose Palazon "Palako" Yahoo! In 2003 Tony Blair was "bytten" by a word document which its metadata demonstrated had been edited. Since that days a lot of advisories warning about to keep free of undesired data all published document shown up around the whole Internet... but times went by and people don't worry s....
|
|
Chris Gates and Mario Ceballos - Breaking the Unbreakable Oracle with Metasploit
-
www.defcon.org
-
16 years ago
-
eng
Breaking the "Unbreakable" Oracle with Metasploit Chris Gates Member of the Metasploit Project Mario Ceballos Developer for the Metasploit Project Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the abilit....
|
|
Bruce Schneier - Question and Answer Session - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..
|
|
Charlie Vedaa and Anonymous - Proxy Prank o Matic - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Proxy Prank-o-Matic Charlie Vedaa Founder @ PacketProtector.org "Anonymous secondary speaker" The Upside-Down-Ternet was just the beginning. What else can you do with a proxy server and a mischievous mind? We'll show you how to send your victims back in time (fun with archive.org), to the all-porn Internet (is there any other kind?), or to the Tourette-net (Cartman runs the Internets)! Via browser settings or port forwarding, using..
|
|
Chema Alonso and Jose Palazon - Tactical Fingerprinting Using Metadata Hidden Info and Lost Data - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data Chema Alonso MVP Enterprise Security, CTO Inform·tica64 Jose Palazon "Palako" Yahoo! In 2003 Tony Blair was "bytten" by a word document which its metadata demonstrated had been edited. Since that days a lot of advisories warning about to keep free of undesired data all published document shown up around the whole Internet... but times went by and people don't worry s....
|
|
Chris Gates and Mario Ceballos - Breaking the Unbreakable Oracle with Metasploit - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Breaking the "Unbreakable" Oracle with Metasploit Chris Gates Member of the Metasploit Project Mario Ceballos Developer for the Metasploit Project Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the abilit....
|
|
Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..
|
|
Proxy Prank-o-Matic Charlie Vedaa Founder @ PacketProtector.org "Anonymous secondary speaker" The Upside-Down-Ternet was just the beginning. What else can you do with a proxy server and a mischievous mind? We'll show you how to send your victims back in time (fun with archive.org), to the all-porn Internet (is there any other kind?), or to the Tourette-net (Cartman runs the Internets)! Via browser settings or port forwarding, using..
|
|
Chema Alonso and Jose Palazon - Tactical Fingerprinting Using Metadata Hidden Info and Lost Data - Slides
-
www.defcon.org
-
16 years ago
-
eng
Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data Chema Alonso MVP Enterprise Security, CTO Inform·tica64 Jose Palazon "Palako" Yahoo! In 2003 Tony Blair was "bytten" by a word document which its metadata demonstrated had been edited. Since that days a lot of advisories warning about to keep free of undesired data all published document shown up around the whole Internet... but times went by and people don't worry s....
|
|
Chris Gates and Mario Ceballos - Breaking the Unbreakable Oracle with Metasploit - Slides
-
www.defcon.org
-
16 years ago
-
eng
Breaking the "Unbreakable" Oracle with Metasploit Chris Gates Member of the Metasploit Project Mario Ceballos Developer for the Metasploit Project Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the abilit....
|
|
Fragging Game Servers Bruce Potter Founder - The Shmoo Group Logan Lodge TFT Ninja Every day, security professionals do battle the trenches; good vs. evil, whitehats vs. blackhats, our network vs their l337 tools. And what do we do to unwind after work? For many of us, it's doing battle in the trenches with terrorists, Nazi's, and that pesky Blue team that keeps stealing our intelligence. Video games are a multi-billion dollar....
|
|
Bruce Potter and Logan Lodge - Fragging Game Servers - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Fragging Game Servers Bruce Potter Founder - The Shmoo Group Logan Lodge TFT Ninja Every day, security professionals do battle the trenches; good vs. evil, whitehats vs. blackhats, our network vs their l337 tools. And what do we do to unwind after work? For many of us, it's doing battle in the trenches with terrorists, Nazi's, and that pesky Blue team that keeps stealing our intelligence. Video games are a multi-billion dollar....
|
|
Fragging Game Servers Bruce Potter Founder - The Shmoo Group Logan Lodge TFT Ninja Every day, security professionals do battle the trenches; good vs. evil, whitehats vs. blackhats, our network vs their l337 tools. And what do we do to unwind after work? For many of us, it's doing battle in the trenches with terrorists, Nazi's, and that pesky Blue team that keeps stealing our intelligence. Video games are a multi-billion dollar....
|
|
Attacking SMS. It's No Longer Your BFF Brandon Dixon Information Systems Security Engineer at G2, Inc. It's the year 2009 and spam mail is still taking up a huge percentage of all email sent everyday over the Internet. Could you imagine that same messaging spam making a detour through your favorite cellular provider gateway and right to your SMS inbox? Mobile spam has not reached the same popularity as email spam, but what if it was ....
|
|
Attacking SMS. It's No Longer Your BFF Brandon Dixon Information Systems Security Engineer at G2, Inc. It's the year 2009 and spam mail is still taking up a huge percentage of all email sent everyday over the Internet. Could you imagine that same messaging spam making a detour through your favorite cellular provider gateway and right to your SMS inbox? Mobile spam has not reached the same popularity as email spam, but what if it was ....
|