|
Robert Ricks: New Tool for SQL Injection with DNS Exfiltration
-
www.defcon.org
-
19 years ago
-
eng
For years people have been warned that blind SQL injection is a problem, yet there are a multitude of vulnerable websites out there to this day. Perhaps people don't realize that these vulnerabilities are very real. The current state of the art tools are Absinthe and SQL Brute for exploiting blind SQL injection. DNS exfiltration has been proposed as a method of reaching previously unassailable blind SQL injection access points. We have crea....
|
|
There have been a number of exciting bugs and design flaws in Tor over the years, with effects ranging from complete anonymity compromise to remote code execution. Some of them are our fault, and some are the fault of components (libraries, browsers, operating systems) that we trusted. Further, the academic research community has been coming up with increasingly esoteric --- and increasingly effective! --- attacks against all anonymity desi....
|
|
Ryan Trost: Evade IDS/IPS Systems using Geospatial Threat Detection
-
www.defcon.org
-
19 years ago
-
eng
IDS/IPS systems are becoming more and more advanced and geocoding is adding another layer of intelligence to try and defend against a company's vulnerabilities. Learn how to evade complex geospatial threat detection countermeasures. Most crackers use zombie machines to launch professional attacks...but zombies even leave geographic fingerprints that are easily picked up by pattern recognition algorithms. Learn how to take professional attac....
|
|
Sandy "Mouse" Clark: Climbing Everest: An Insider's Look at one state's Voting Systems
-
www.defcon.org
-
19 years ago
-
eng
Hanging Chads, Hopping votes, Flipped votes, Tripled votes, Missing memory cards, Machine malfunctions, Software glitches, Undervotes, Overvotes. Reports of voting machine failures flooded the news after the last elections and left most voters wondering "Does my vote really count?" "Can these electronic voting machines be trusted?" "How secure are my state's voting systems?" In December 2007, we published an in depth, source code and h....
|
|
Schuyler Towne & Jon King: How to make Friends & Influence Lock Manufacturers
-
www.defcon.org
-
19 years ago
-
eng
Locksport is growing up in America. In this talk we will explore four case studies demonstrating how the community has leveraged itself to bring about significant advances in the lock industry. We will demonstrate exploits discovered in both Medeco and ABUS high security locks and discuss how Kwikset's Smartkey system responded to the spread of information about bumping and how they plan to work with the community in the future. We will inv....
|
|
If the only requirement for you to become a Computer Forensic person is to be a Private Investigator, why would you ever take a certification again? You would never need to be a CCE (computer certified examiner), nor any other certification of any kind. You would be one of the only people in your area that could legally do the job and why spend a single dime you don't have to? These new laws will destroy certifications and qualifications as....
|
|
Scott Moulton: Solid Stated Drives Destroy Forensic & Data Recovery Jobs: Animated!
-
www.defcon.org
-
19 years ago
-
eng
This speech is all ANIMATION in 3D! Data on a Solid State Device is virtualized and the Physical Sector that you are asking for is not actually the sector it was 5 minutes ago. The data moves around using wear leveling schemes controlled by the drive using propriety methods. When you ask for Sector 125, its physical address block is converted to an LBA block and every 5 write cycles the data is moved to a new and empty previously erased blo....
|
|
In 2007 SensePost demonstrated the how DNS and Timing attacks could be used for a variety of attacks. This year we take those attacks further and show how small footholds in a target network can be converted into portals we can (and do) drive trucks through! With some updated SensePost tools, and some brand new ones, we will demonstrate how to convert your simple SQL Injection attacks (against well hardened environments) into point and clic....
|
|
Signaure-based Antivirus is dead, we want to show you just how dead it is. This presentation will detail our findings from running the Race-2-Zero contest during DC16. The contest involves teams or individuals being given a sample set of malicious programs to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat. The first to ....
|
|
Taylor Banks & Carric: Pen-Testing is Dead, Long Live the Pen Test
-
www.defcon.org
-
19 years ago
-
eng
This talk explores the death and subsequent re-birth of the penetration test. Comprised of conclusions drawn from the collective experiences of two seasoned pen-testers, our talk is filled with facts, fun and rhetoric. We will describe the landscape, the problems, and offer real solutions. In our talk, we will explore the problems with modern-day pen-tests and pen-testers, and ways to stand out amongst the frauds selling their lackluster....
|
|
Thomas d'Otreppe de Bouvette aka Mister_X & Rick Farina:Shifting the Focus of WiFi Security: Beyond cracking your neighbor's wep key
-
www.defcon.org
-
19 years ago
-
eng
In this talk we will discuss the paradigm shift of WiFi attacks away from the Access Points and focusing toward the clients. We will cover in depth how simple tricks such as HoneyPot Access Points or even hotspotter simply are not enough anymore and more flexible and powerful methods are being developed and used. The older, dated technologies built into Access Points for ensuring network security have failed the test of time paving way for ....
|
|
There has been a recent global push for the creation of Hacker Spaces. Unfortunately, these ventures are risky and can be quite costly. In an effort to provide an alternative, or at least an intermediary step, this talk will discuss a different type of Hacker Space, one that is on wheels. During the course of this speech, we will discuss the advantages and disadvantages of building a mobile hacker space, and present a real-world example, wh....
|
|
Tom Stracener & Robert Hansen: Xploiting Google Gadgets: Gmalware and Beyond
-
www.defcon.org
-
19 years ago
-
eng
Google Gadgets are symptomatic of the Way 2.0 Way of things: from lame gadgets that rotate through pictures of puppies to calendars, and inline email on your iGoogle homepage. This talk will analyze the security history of Google Gadgets and demonstrate ways to exploit Gadgets for nefarious purposes. We will also show ways to create Gadgets that allow you to port scan internal systems and do various JavaScript hacks via malicious (or useful....
|
|
Tony Howlett: The Death of Cash:The loss of anonymity and other dangers of the cash free society
-
www.defcon.org
-
19 years ago
-
eng
In this talk, we will discuss the pros and cons (mostly cons) of the cash less society and how it might endanger your privacy and civil liberties. This movement towards the elimination of cash has been picking up speed and mostly accepted by the populace as a huge convenience. We examine some reasons why this isn't such a good thing. We also look at legislation and laws in this area that give banks and the government unprecedented ability t....
|
|
Tottenkoph,Rev & Philosopher: Hijacking the Outdoor Digital Billboard Network
-
www.defcon.org
-
19 years ago
-
eng
Outdoor digital billboards are becoming the new way to advertise multiple products/services/etc with a single board as compared to having a street littered with dozens of these eyesores. Therefore, they're more fun to take apart and play with. While driving one day, I noticed a 404 error on one of these billboards and after discussing it with my fellow speakers, hatched a plan to hack into their network and advertise our own ideas/ "product....
|
|
In 1990, a wire-bound book was published in Paris by the title of "Voyage au centre de la HP28 c/s". It presents a very thorough account of the inner workings of the Hewlett Packard 28 series of graphing calculators. Designed before the days of prepackaged microprocessors, the series uses the Saturn architecture, which HP designed in-house. This architecture is very different from today's homogeneous RISC chips, with registers of 1, 4, 12, ....
|
|
When penetration testing large environments, testers require the ability to maintain persistent access to systems they have exploited, leverage trusts to access other systems, and increase their foothold into the target. Post exploitation activities are some of the most labor intensive aspects of pen testing. These include password management, persistent host access, privileged escalation, trust relationships, acquiring GUI access, etc. Pen....
|
|
Vic Vandal: Keeping Secret Secrets Secret and Sharing Secret Secrets Secretly
-
www.defcon.org
-
19 years ago
-
eng
Have you ever wanted to: * Transmit secret codes and messages * Protect Nuclear launch codes * Dabble in Intellectual Property protection * Warez/file-sharing with legal liability protection * Develop and share terrorist plots * Smuggle illegal substances * Hide digital pr0n from others * Exchange classified information securely * Exchange diskette with "Leonardo da Vinci" virus, culled from the hacked "garbage....
|
|
Compliance is no longer new. Compliance has been accepted by the corporate-state. Compliance is common-place. Compliance is the intruders' new friend. Decision makers thinks Compliance == Security. While many compliance standards have resulted in the implementation of some very important controls, they have also left a roadmap for intruders, ill doers and the sort to hone their attack. This presentation will go over such weaknesses and show..
|
|
Wendel Guglielmetti Henrique: Playing with Web Application Firewalls
-
www.defcon.org
-
19 years ago
-
eng
WAF (Web Application Firewalls) are often called 'Deep Packet Inspection Firewalls' because they look at every request and response within the HTTP/HTTPS/SOAP/XML-RPC/Web Service layers. Some WAFs look for certain 'attack signatures' to try to identify a specific attack that an intruder may be sending, while others look for abnormal behavior that doesn't fit the websites normal traffic patterns. Web Application Firewalls can be either softw....
|
|
Need help understanding your gigabytes of application logs or network captures? Your OS performance metrics do not make sense? Then DAVIX, the live CD for visualizing IT data, is your answer! To simplify the analysis of vast amounts of security data, visualization is slowly penetrating the security community. There are many free tools available for analysis and visualization of data. To simplify the use of these tools, the open source ....
|
|
Zac Franken: Is that a unique credential in your pocket or are you just happy to see me?
-
www.defcon.org
-
19 years ago
-
eng
This year new shiny toys are abound, as I'll tell you about the credentials in your wallet, and even in you. How secure (or not) they are and a few ways to duplicate / replicate /emulate them. Last year at Defcon 15 I had a bit of a chat with you guys and gave you an overview of access control systems, told you of their common flaw, and showed you some cool toys that exploit it. This year, from the humble magnetic stripe card to the mo....
|
|
Bio: Joe Grand is an electrical engineer and prolific inventor with four pending patents and 19 commercially-available products. Involved in computers and electronics since the age of 7, Joe has had the fortune of being a former member of the legendary Boston-based hacker collective L0pht Heavy Industries, testifying before the United States Senate Governmental Affairs Committee under his nom de hack, Kingpin, and being praised as a "moder..
|
|
Thomas X. Grasso: Fighting Organized Cyber Crime: War Stories and Trends
-
www.defcon.org
-
19 years ago
-
eng
Abstract: As one of the pioneers of partnerships for the FBI, Thomas X. Grasso, Jr. of the FBI's Cyber Division will outline how the FBI has taken this concept from rhetoric to reality over the past 5 years. This presentation will explore how the mantra "make it personal" has aided the FBI in forging exceptional alliances with key stake holders from industry, academia and ln a enforcement both domestically and abroad. This presentation wil....
|
|
Atlas: The Making of atlas: Kiddie to Hacker in 5 Sleepless Nights
-
www.defcon.org
-
19 years ago
-
eng
Abstract: atlas was just a kiddie when asked to write his first exploit in order to qualify for dc13's capture-the-flag. After conquering his sense of inadaquacy, he went on to win the individual competitiion and finish third even among the teams. This presentation will introduce you to atlas, to hacking, and to the pivotal "Stage 3 Binary" which turned the man's life upside down. The talk will be an entertaining walk through his efforts t....
|
|
Abstract: Birth, School, Work, Death. Imagine every web search you've ever done placed on a timeline of your life. Is there anything on that list you wouldn't want your mother (or employer) to know about? How about the aggregate web searches of your entire company? What if they fell into the hands of a competitor? Recent trends indicate that we can no longer rely on the privacy policies of individual web companies to keep this information ....
|
|
Abstract: In the first half of this session, Paul Simmonds will present on behalf of the Jericho Forum taking participants through the initial problem statement and what people need to go away and start implementing. Topics will include: 1. De-perimeterization - the business imperative 2. From protocols to accessing the web - the technical issues 3. What should be implemented today - current and near term solutions 4. Planning for tomo....
|
|
Matt Hargett: Remote Pair Programming and Test-driven Development Using Open Source
-
www.defcon.org
-
19 years ago
-
eng
Abstract: Binary disassembling and manual analysis to find exploitable vulnerabilities is a cool topic. What's cooler? Saving yourself hours of time and brain rot by letting a program do the hard parts for you! In this talk, we will dissect a well-known exploitable vulnerability as well as an open source tool for automatically detecting that vulnerability. By the end of the talk, you will understand the basics of static code analysis, expl....
|
|
Abstract: The Church of Wifi (reformed) has been busy coming up with new and wonderful wireless shenanigans. At Shmoocon we sped up WPA cracking 3 fold, at Layerone we made it even faster, now we take it even further, to places and sizes not dared before: WPA2! When we aren't breaking WPA or cavorting with Evil Bastards, we are thinking about the future. With so many networking devices running embedded OSS software, they are almost whole ....
|
|
Richard Thieme: Beyond Social Engineering: Tools for Reinventing Yourself
-
www.defcon.org
-
19 years ago
-
eng
Abstract: Managing multiple modular identities is not a trivial task. But that's what the technologies and politics of Now demand. These tools will enable you to create personas at a deep level, then link them into a seamless life. Bio: Richard Thieme is a business consultant, writer, and professional speaker focused on "life on the edge," in particular the human dimension of technology and work. He is a contributing editor for Informati....
|
|
Abstract: In this panel session we will begin with a short introductory presentation from Gadi Evron on the latest technologies and operations by the Bad Guys and the Good Guys. What's going on with Internet operations, global routing, botnets, extortion, phishing and the annual revenue the mafia is getting from it. The panel session itself will be hosted by mudge. The members will accept questions on any subject related to the topic at ha....
|
|
Rick Hill: WarRocketing :Network Stumbling 50 sq. miles in <60 sec.
-
www.defcon.org
-
19 years ago
-
eng
WarRocketing : Network Stumbling 50 sq. miles in <60 sec. Rick Hill, Senior Scientist, Tenacity Solutions, Inc. Abstract: Network "stumbling" has taken many forms since Marcus Milner first released Netstumbler in May 2001. Historically, stumbling aficionados preferred data collection method has been Wardriving. Almost everyone owns a car and it's easy to fire up your laptop and drive around. Of course, other methods exist, creative soul....
|
|
Abstract: Trusted computing is not inherently evil. It sounds scary, but it's true. While the public perception of trusted computing is that content providers will use trusted computing to enforce their digital rights and take away our civil liberties (whew! a mouthful), the reality is that there is a lot of good to be done by trusted computing. For more than thirty years, computer scientists have been trying to find ways to make trusted ....
|
|
Abstract: The proliferation of malware is a serious problem, which grows in sophistication and complexity every day, but with this growth, comes a price. The price that malware pays for advanced features and sophistication is increased vulnerability to attack. Malware is a system, just like an OS or application. Systems employ security mechanisms to defend themselves and also suffer from vulnerabilities which can be exploited. Malware is n....
|
|
Abstract: Smart phones are the new favorite target of many attackers. Also most current attacks are harmless, since these mostly rely on user mistake or lack of better knowledge. Current attacks are mostly based on logic errors rather then code inject and often are only found by accident. The talk will show some real attacks against smart phones and the kind of vulnerability analysis which lead to their discovery. Bio: Collin Mulliner is..
|
|
Abstract: Security competitions have been of interest to many individuals for a number of years. The popularity of the annual DEFCON competition demonstrates the level of interest in these events. This talk will discuss the creation of the National Collegiate Cyber Defense Competition which was held in April 2006. A brief history covering the development of this competition will be covered as well as a discussion of the event itself. The r....
|
|
Scott Moulton: Rebuilding HARD DRIVES for Data Recovery; Anatomy of a Hard Drive
-
www.defcon.org
-
19 years ago
-
eng
Abstract: Every hard drive will die a quick and sudden death sooner rather than later. What happens after that death can be very important to your data and become the deciding factor in its survival. We will display the inner workings of a hard drive in a beautiful animation and discuss the successes and failures in rebuilding a hard drive. We will teach you what to look for and how to accomplish this task on your own. We will delve into t....
|
|
Abstract: It's been a year since Major Mal gave his talk on hotel IR systems, and things haven't got any better...In fact, they've got worse. No, wait a minute...that's not right...They've *stayed* worse!! Having plumbed the depths of the IR in his room, and finding himself with little else to do, Major turned his attention to another piece of technology easily to hand: his magstripe room key...Now these have been around since Mary checked....
|
|
Thomas Holt: Exploring the Changing Nature of DEFCON over the Past 14 Years
-
www.defcon.org
-
19 years ago
-
eng
Abstract: DEFCON began in 1993 as an "orgy of information exchange, viewpoints, speeches, education, enlightenment...and most of all sheer, unchecked PARTYING."(DEFCON 1 Announcement, 1993). Fourteen years later, the convention is one of the most established hacker conventions, and is defined as "the largest underground hacking convention in the world."However, significant social and technological changes have occurred during this period. ....
|
|
Abstract: In this day and age, forensics evidence lurks everywhere. The task presented to modern forensics investigators is a daunting one. During this talk, you'll slip into the shoes of an uber-agent hot on the trail of the illustrious Knuth from the Stealing the Network series. Haven't read the latest installation? You should. How would YOU catch a guy that MELTED his hard drive platters and sanded down all his CDs? Where's the evidence....
|
|
Strom Carlson: Hacking FedEx Kinko's: How Not To Implement Stored-Value Card Systems
-
www.defcon.org
-
19 years ago
-
eng
ExpressPay is a stored-value cash card system which utilizes the Infineon SLE4442 chip; it was developed by enTrac Technologies of Toronto, Ontario, and its largest application is as the pre-paid cash card system in use at FedEx Kinko's. Analysis of a few dozen cards reveals that the data stored on the card is unencrypted and poorly protected against fraud, and a simple attack can be used to obtain the security code necessary to alter the d..
|
|
Robert Clark: Legal Aspects of Internet & Computer Network Defense - A Year in Review Computer and Internet Security Law 2005-2006
-
www.defcon.org
-
19 years ago
-
eng
Abstract: This presentation looks at computer network defense and the legal cases of the last year that affect internet and computer security. This presentation clearly and simply explains (in non-legal terms) the legal foundations available to users and service providers to defend their networks. Quickly tracing the legal origins from early property common-law doctrine into today?s statutes and then moving into recent court cases and ba....
|
|
Amber Schroader: Cyber-crime Foiled Once Again? Help prove the innocence or guilt of Jack Grove
-
www.defcon.org
-
19 years ago
-
eng
Abstract: Jack Grove tries to stop his racing heart as he slips into a dark dingy alley. His paranoia is getting the best of him as he looks behind him. No one is following him, but he senses they are coming. He is afraid. The hack hadn't gone down as planned. Damn it, he was supposed to have taken everything into account, he got sloppy. He knew his only saving grace was no one would be able to recover his laptop. Not after what he did to i....
|
|
Abstract: Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation?s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as NSA wiretapping, cellphone tracking by the government, bloggers? rights and online journalism, the Sony rootkit scanda....
|