I previously showed you how to Load a Github Gist with Composer, but sometimes you need to install code that isn't isn't even in a public facing VCS. I for instance wanted to use a library only distributed by Zip. It's actually fairly easy! In your composer.json file, you simply add a repositories section to the root. You will want to update the url section to point at the remote zip you intend to load, as well as updating the name an..
|
I previously showed you how to Load a Github Gist with Composer, but sometimes you need to install code that isn't isn't even in a public facing VCS. I for instance wanted to use a library only distributed by Zip. It's actually fairly easy! In your composer.json file, you simply add a repositories section to the root. You will want to update the url section to point at the remote zip you intend to load, as well as updating the name an..
|
|
I just patched puppet-gluster and puppet-ipa to bring their infrastructure up to date with the current state of affairs… What’s new ? Better README's Rake syntax checking (fewer oopsies) CI (testing) with travis on git push (automatic testing for everyone) Use of .pmtignore to ignore files from puppet module packages (finally) Pushing modules to the forge with blacksmith (sweet!) This last point deserves another mention...
|
|
I just patched puppet-gluster and puppet-ipa to bring their infrastructure up to date with the current state of affairs… What’s new ? Better README's Rake syntax checking (fewer oopsies) CI (testing) with travis on git push (automatic testing for everyone) Use of .pmtignore to ignore files from puppet module packages (finally) Pushing modules to the forge with blacksmith (sweet!) This last point deserves another mention...
|
|
I've been using tmux for a while, and even though I didn't like it at first, now I'm in love with it. I'm mostly using it as a GNU Screen alternative, but I don't use some of its fancy features like tabs, mainly because my window manager takes care of multiple terminal windows for me.
|
|
Another article courtesy of the folks over at Gear Patrol, this time a photo essay after a trip to South Africa’s Sabi Sands Game Reserve. I spent three months in South Africa a number of years ago, and hours upon days trolling through an adjacent park (Kruger National Park, for those curious), but only managed to see a fraction of the sights the folks did here. Even then, though, I have no complaints: Africa was full of majesty everywhere ..
|
|
The recent surge in attention to searchcode from the Windows 9/10 naming fiasco resulted in a lot of questions being raised about searchcode’s policy about free software (open source). While the policy is laid out on the about page some have raised the issue of the ethics about using such a website which is not 100% free (as in freedom). For the purposes of the rest of this post “free software” is going to refer to software defined as n..
|
|
The first commandment that any young programmer learns is “Thou Shall Not Duplicate”. Thus instructed, whenever we see something that looks like it may be repeated code, we refactor. We create libraries and frameworks. But removing duplication doesn’t come for free. If I refactor some code so that instead of duplicating some logic in Class A and Class B, these classes share the logic in Class R (for reuse!). Now Classes A and B are indirect..
|
|
I'm working on integrating the Oculus Rift DK2 with the Ogre3D engine . Last night I got basic head tracking working: moving the DK2 in real life translates into camera movement in-game. The goal is to build a toolkit that makes building something for the Rift in Ogre super duper easy. comments
|
|
Sol Orwell is the co-founder of Examine.com, an independent encyclopedia for supplement and nutrition information.
|
|
You really can't be serious about building websites these days they're not optimised for mobile so it was high time I grok-ed the key concepts of responsive design.
|
|
Although I started out confident in Coin’s eventual success , I have since made no bones about my distaste for their questionable methodologyy , business model , and apparent inability to meet deadlines . Burn me once, shame on you; burn me twice, though, shame on me: I’m hesitant to get behind Plastc given the apparently insurmountable challenges of this space, but that won’t stop me from wishing them success. At this point, I just wan..
|
|
The brain thing is really getting out of control. Yesterday I ran into this problem: Fatal error: Maximum function nesting level of '100' reached, aborting!
|
|
Additional C/C++ Tooling . C++ Best Practices . C++ Core Guidelines . cppreference.com . Fast directory listing . FunctionalPlus: helps you write concise and readable C++ code . GitHub - mozilla/rr: Record and Replay Framework (debugging) . Modern C | Hacker News . Modern C++: Variadic template parameters and tuples . My favorite C compiler flags during development | Hacker News . My Most Important C++ Aha! Moments…Ever . Program..
|
|
On 23 and 25 September Thoughtworks hosted the first edition of XConf in Europe. XConf is a one-day conference that showcases the latest thinking from Thoughtworks and friends on a broad range of technology topics. It provides a platform for passionate technologists who are looking for inspiration and a chance to network with their peers.
|
|
In a day and age before ubiquitous personal drones roamed the skies, capturing incredible footage of active volcanoes, for example , filmmakers had no choice but to climb into planes and film those breathtaking views themselves. Harrison Sanborn found some of this footage in his father’s archives, digitized the film, and turned the result into a neat three minute video on Vimeo. There’s a certain quality to this footage that newer, digit..
|
|
An incredible, remarkably powerful story by Alan Heathcock that seeks to lay the harsh realities of drought to bear with a painful, hard-hitting story of good people who have lost everything for lack of one sample necessity: water. This article ought to be a prerequisite for forming any opinions on sustainability whatsoever. Permalink.
|
|
Reducing code complexity though conventions and stop services and controllers turning into a dumping ground for core logic
|
|
Pair programming has been used by software developers in most progressive software companies to help churn out quality products and ensure that context is shared across the teams. For the uninitiated, traditional pair programming is a practice where 2 programmers work on developing a piece of software functionality in tandem.
|
Practical Foxhunting 101 Adam Wirth (SimonJ) COMMUNICATIONS SYSTEMS ENGINEER, MASTERPEACE SOLUTIONS LTD The basic skills needed to quickly locate wireless emitters are easy to learn and no special equipment is required. Despite this, relatively few people have the know-how to put their equipment to work locating emitters as part of penetration testing, RF environment mapping, or tracking their geriatric neighbors using the emanations fr....
|
Extra Materials are available here: https://www.defcon.org/images/defcon-22/dc-22-presentations/Valtman/DEFCON-22-Nir-Valtman-Extras-Bug-Bounty-Programs-Evolution.zip Bug Bounty Programs Evolution Nir Valtman ENTERPRISE SECURITY ARCHITECT Bug bounty programs have been hyped in the past 3 years, but this concept was actually widely implemented in the past. Nowadays, we can see big companies spending a lot of money on these programs, wh....
|
Anatomy of a Pentest; Poppin' Boxes like a Pro PushPin Are you excited about hacking and want to be a pentester in the next few years? Let this talk be your guide in understanding what is required to effectively assess a network and all of its associated components. We’ll review subjects ranging from assessment toolsets, environment configurations, timelines, what to do when you’ve accidentally brought down the entire finance department....
|
|
Tim Strazzere and Jon Sawyer - Android Hacker Protection Level 0
-
www.defcon.org
-
11 years ago
-
eng
Android Hacker Protection Level 0 Tim Strazzere LEAD RESEARCH & RESPONSE ENGINEER Jon Sawyer CTO OF APPLIED CYBERSECURITY LLC Obfuscator here, packer there - the Android ecosystem is becoming a bit cramped with different protectors for developers to choose. With such limited resources online about attacking these protectors, what is a new reverse engineer to do? Have no fear, after drinking all the cheap wine two Android hackers have ....
|
|
Nemus - An Introduction to Back Dooring Operating Systems for Fun and Trolling
-
www.defcon.org
-
11 years ago
-
eng
An Introduction to Back Dooring Operating Systems for Fun and Trolling Nemus SECURITY RESEARCHER So you want to setup a back door? Have you ever wondered how its done and what you can do to detect back doors on your network and operating systems? Ever wanted to setup a back door to prank a friend?. This presentations will do just that. We will go over the basics of back doors using SSH, NET CAT, Meterpreter and embedding back doors into....
|
|
Lucas Morris and Michael McAtee - ShareEnum: We Wrapped Samba So You Don’t Have To
-
www.defcon.org
-
11 years ago
-
eng
ShareEnum: We Wrapped Samba So You Don’t Have To Lucas Morris MANAGER, CROWE HORWATH Michael McAtee SENIOR CONSULTANT, CROWE HORWATH CIFS shares can tell you a lot about a network, including file access, local administrator access, password reuse, etc.. Until now most people have relied on add-ons to scanning tools to implement Microsoft’s complicated network APIs. Some tools wrap existing clients, such as smbclient, or use RPC calls;....
|
|
Metacortex and Grifter - Touring the Darkside of the Internet. An Introduction to Tor, Darknets, and Bitcoin
-
www.defcon.org
-
11 years ago
-
eng
Touring the Darkside of the Internet. An Introduction to Tor, Darknets, and Bitcoin Metacortex SECURITY RESEARCHER Grifter SECURITY RESEARCHER This is an introduction level talk. The talk itself will cover the basics of Tor, Darknets, Darknet Market places, and Bitcoin. I will start by giving the audience an overview of Tor and how it works. I will cover entry nodes, exit nodes, as well as hidden services. I will then show how you con....
|
USB for all! Jesse Michael SECURITY RESEARCHER Mickey Shkatov SECURITY RESEARCHER USB is used in almost every computing device produced in recent years. In addition to well-known usages like keyboard, mouse, and mass storage, a much wider range of capabilities exist such as Device Firmware Update, USB On-The-Go, debug over USB, and more. What actually happens on the wire? Is there interesting data we can observe or inject into these o....
|
|
RMellendick and DaKahuna - RF Penetration Testing, Your Air Stinks
-
www.defcon.org
-
11 years ago
-
eng
RF Penetration Testing, Your Air Stinks RMellendick (RICK MELLENDICK) DaKahuna (JOHN FULMER) The purpose of this talk is to discuss the effective radio frequency (RF) tools, tactics, and procedures that we recommend security professionals use when performing a repeatable RF penetration test. This talk will cover the fundamental processes used to identify the RF within the environment, identify the vulnerabilities specific to that envi....
|
|
Medic (TIM MCGUFFIN) - One Man Shop: Building an effective security program all by yourself
-
www.defcon.org
-
11 years ago
-
eng
One Man Shop: Building an effective security program all by yourself Medic (TIM MCGUFFIN) At past DEF CON events, including DEF CON 101, most of the attendees we’ve encountered were either new to the field of security or had security functions in their job description on top of other job duties such as system administration or programming. The purpose of this talk, which is based on real world experiences, is to introduce a multi-year a....
|
|
Wesley McGrew- Instrumenting Point-of-Sale Malware: A Case Study in Communicating Malware Analysis More Effectively
-
www.defcon.org
-
11 years ago
-
eng
Additional Materials available: https://www.defcon.org/images/defcon-22/dc-22-presentations/McGrew/DEFCON-22-Wesley-McGrew-Instrumenting-Point-of-Sale-Malware-WP.pdf Instrumenting Point-of-Sale Malware: A Case Study in Communicating Malware Analysis More Effectively Wesley McGrew ASSISTANT RESEARCH PROFESSOR, MISSISSIPPI STATE UNIVERSITY The purpose of this talk is to promote the adoption of better practices in the publication and ....
|
|
Geoff McDonald - Meddle: Framework for Piggy-back Fuzzing and Tool Development
-
www.defcon.org
-
11 years ago
-
eng
Meddle: Framework for Piggy-back Fuzzing and Tool Development Geoff McDonald ANTI-VIRUS RESEARCHER AT MICROSOFT Towards simplifying the vulnerability fuzzing process, this presentation introduces a moddable framework called Meddle that can be used to piggy-back on existing application’s knowledge of protocol by performing piggy-back fuzzing. Meddle is an open source Windows x86 and x64 user-mode C# application that uses IronPython plugi....
|
|
Chris Littlebury - Home Alone with localhost: Automating Home Defense
-
www.defcon.org
-
11 years ago
-
eng
Home Alone with localhost: Automating Home Defense Chris Littlebury SENIOR PENETRATION TESTER, KNOWLEDGE CONSULTING GROUP, INC. Home automation is everywhere, and so are their exploits. This presentation will go over a brief history of home automation techniques, cover modern technologies used today, detail some of the current exploits used against modern automation and security systems, and give examples on how to defend against them. ..
|
|
Jake Kouns and Carsten Eiram - Screw Becoming A Pentester - When I Grow Up I Want To Be A Bug Bounty Hunter!
-
www.defcon.org
-
11 years ago
-
eng
Screw Becoming A Pentester - When I Grow Up I Want To Be A Bug Bounty Hunter! Jake Kouns CISO, RISK BASED SECURITY Carsten Eiram CHIEF RESEARCH OFFICER, RISK BASED SECURITY Everywhere you turn it seems that companies are having serious problems with security, and they desperately need help. Getting into information security provides an incredible career path with what appears to be no end in sight. There are so many disciplines that y....
|
|
Kyle Kelley and Greg Anderson - Is This Your Pipe? Hijacking the Build Pipeline.
-
www.defcon.org
-
11 years ago
-
eng
Is This Your Pipe? Hijacking the Build Pipeline. Kyle Kelley DEVELOPER SUPPORT ENGINEER, RACKSPACE Greg Anderson SOFTWARE SECURITY ENGINEER,RACKSPACE As developers of the web, we rely on tools to automate building code, run tests, and even deploy services. What happens when we're too trusting of CI/CD pipelines? Credentials get exposed, hijacked, and re-purposed. We'll talk about how often and what happens when people leak public clou....
|
|
Ryan Kazanciyan and Matt Hastings, Investigating PowerShell Attacks
-
www.defcon.org
-
11 years ago
-
eng
Investigating PowerShell Attacks Ryan Kazanciyan TECHNICAL DIRECTOR, MANDIANT Matt Hastings CONSULTANT, MANDIANT Over the past two years, we've seen targeted attackers increasingly utilize PowerShell to conduct command-and-control in compromised Windows environments. If your organization is running Windows 7 or Server 2008 R2, you've got PowerShell 2.0 installed (and on Server 2012, remoting is enabled by default!). This has created a....
|
|
Anch - The Monkey in the Middle: A pentesters guide to playing in traffic.
-
www.defcon.org
-
11 years ago
-
eng
The Monkey in the Middle: A pentesters guide to playing in traffic. Anch (MIKE GUTHRIE) Prank your friends, collect session information and passwords, edit traffic as it goes by.. become the Monkey(man)-In-The-Middle and do it all… This presentation will teach you a penetration testers view of man in the middle (MITM) attacks. It will introduce the tools, techniques and methods to get traffic to your hosts. Demonstrations of the tools....
|
NSA Playset: PCIe Joe FitzPatrick HARDWARE SECURITY RESOURCES, LLC Miles Crabill SECURITY RESEARCHER Hardware hacks tend to focus on low-speed (jtag, uart) and external (network, usb) interfaces, and PCI Express is typically neither. After a crash course in PCIe Architecture, we'll demonstrate a handful of hacks showing how pull PCIe outside of your system case and add PCIe slots to systems without them, including embedded platforms. ....
|
Reverse Engineering Mac Malware Sarah Edwards SANS INSTITUTE Dynamic malware reverse engineering helps forensic analysts and reverse engineers gather quick data points such as callout domains, file download URLs or IP addresses, and dropped or modified files. These methods have long been used on Windows malware...so why not Mac malware? This presentation introduces the audience to methods, tools, and resources to assist reversing Mac bi....
|
|
Jim Denaro and Tod Beardsley - How to Disclose an Exploit Without Getting in Trouble
-
www.defcon.org
-
11 years ago
-
eng
How to Disclose an Exploit Without Getting in Trouble Jim Denaro CIPHERLAW Tod Beardsley ENGINEERING MANAGER, METASPLOIT PROJECT You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This session will cover the risks to security researchers involved in publishing or selling in....
|
|
Jeff Kish, contributing editor at the excellent site GearJunkie, spent the summer hiking 1,200 miles on the Pacific Northwest Trail. I followed his journey from that first report in July all the way up to this the conclusion of his trek, and I have to say: I’m both jealous and impressed. If you had the misfortune of missing this great series, head over and check it out: it’s well-worth your time. Follow Thru-Hike Of “Pacific Northwest Trai..
|
|
Oracle In-Memory Column Store Internals – Part 1 – Which SIMD extensions are getting used?
-
tanelpoder.com
-
11 years ago
-
eng
This is the first entry in a series of random articles about some useful internals-to-know of the awesome Oracle Database In-Memory column store . I intend to write about Oracle’s IM stuff that’s not already covered somewhere else and also about some general CPU topics (that are well covered elsewhere, but not always so well known in the Oracle DBA/developer world). Before going into further details, you might want to review the Part 0 ..
|