|
Fabian "Fabs" Yamaguchi & FX: New ideas for old practices - Port-Scanning improved
-
www.defcon.org
-
19 years ago
-
eng
How fast a port-scan can be is largely dependent on the performance of the network in question. Nonetheless, it is clear that choosing the most efficient scanning-speed is only possible based on sufficient information on the network's performance. We have thus designed and implemented a port-scanning method which provokes extra network-activity to increase the amount of information at our disposal in an attempt to gain speed on the long run....
|
|
Thanks to Web 2.0 and other over hyped BS, development has been moving farther and farther away from bare metal. Assuming you trust your libraries, this could even be called a good thing. If you're high." PC gaming, despite Microsoft's best efforts, is not dead. Yet. The modding community is alive and active, and even those same over hyped web technologies are starting to encroach in to shaders, and other things they shouldn't touch. L....
|
|
Fouad Kiamilev & Ryan Hoover: Demonstration of Hardware Trojans
-
www.defcon.org
-
19 years ago
-
eng
Recent developments such as the FBI operation "Cisco Raider" that resulted in the discovery of 3,500 counterfeit Cisco network components show the growing concern of U.S. government about an electronic hardware equivalent of a "Trojan horse". In an electronic Trojan attack, extra circuitry is illicitly added to hardware during its manufacture. When triggered, the hardware Trojan performs an illicit action such as leaking secret information,....
|
|
Attacks on network infrastructure are not a new field. However, the increasing default protections in common operating systems, platforms and development environments increase interest in the less protected infrastructure sector. Today, performing in-depth crash analysis or digital forensics is almost impossible on the most widely used routing platform. This talk will show new developments in this sector and how a slightly adjusted net....
|
|
The talk focuses on 1D and 2D barcode applications with interference possibilities for the ordinary citizen. Ever wondered what is in these blocks of squares on postal packages, letters and tickets? Playing with them might have interesting effects, reaching from good old fun to theft and severe impact. Barcodes have been around for ages, but most of the time were used as simple tags with a number. The rise of 2D barcodes started to put....
|
|
The Nmap Security Scanner was built to efficiently scan large networks, but Nmap's author Fyodor has taken this to a new level by scanning millions of Internet hosts as part of the Worldscan project. He will present the most interesting findings and empirical statistics from these scans, along with practical advice for improving your own scan performance. Additional topics include detecting and subverting firewall and intrusion detection sy....
|
|
Take a trip back in time and discover what hacking was like in the pioneer days -- before the Internet, the PC, or even the Commodore 64 or TRS-80. The speaker started "exploring" computer systems in 1973, when the only law about hacking was the hacker ethic itself. Join a humorous reminiscence about what it was like building an Altair 8800, "discovering" the 2600 Hz tone, storing programs on punched cards, cracking bad crypto, and more. Yo..
|
|
Greg Conti: Could Googling Take Down a President, a Prime Minister, or an Average Citizen?.
-
www.defcon.org
-
19 years ago
-
eng
Every time we use the web, we disclosure tremendous amounts of information to ISPs, Internet backbone providers, and online companies; information that will be shared and data mined, but rarely discarded. Email addresses, phone numbers, aggregated search queries, cookies, IP addresses - any unique feature of our behavior provides a mechanism to link, profile, and identify users, groups, and companies. From these revelations all aspects of o....
|
|
Cable modems are widely used these days for internet connections or other applications. This talk gives a detailed overview of this mean of communication with a focus on its security. DOCSIS (Data Over Cable Service Interface Specification) is currently the most used protocol around the world for providing internet over TV coaxial cable. Due to its nature, this protocol can easily be sniffed by taping onto the TV cable using a digital ....
|
|
In this talk Professor Angell will take the Devils advocate position, warning that computer technology is part of the problem as well as of the solution. The belief system at the core of computerization is positivist and/or statistical, and that itself leads to risk. The mixture of computers and human activity systems spawns bureaucracy and systemic risk, which can throw up singularities that defy any positivist/statistical analysis. Using ....
|
|
What do you want? This is the question that almost every commercial organization on the planet thinks they have an answer to, but do they? Figuring out what people want is essentially a process of reverse engineering human needs, desire, and preference. It turns out that hackers are particularly adept at reverse engineering, so what happened when we applied our skills to reverse engineering what you, and everyone else, wants? This talk....
|
|
This session will discuss the risks associated with creation of replicating code. A combination of wide availability of virus source code as well as the problem of control over replicating code make these experiments quite risky. To demonstrate these points we shall see how a computer virus was once created unintentionally in a self-modifying tool called ALREADY.COM (we'll disassemble and debug it). We shall watch a video of the "Corrupted ....
|
|
This talk will reintroduce classic steganographic techniques to use with serializing, watermarking, or stashing your data in the latest Internet meme. Why not let everyone who is forwarding yet another painful nut-shot AFHV clip store your data for you? We will create a simple filesystem that is robust enough to survive conversion, and building a structure to organize the data, focusing on indirection and fault tolerance. Jim has over ..
|
|
In order to prevent music from being copied among consumers, content providers often use DRM systems to protect their music files. This talk describes the approach taken while analysing a DRM system (whose identity needs to be kept secret due to legal issues). It is shown what techniques were used to protect the system from being easily reverse engineered. This is not about how to hack $Insert_DRM_Here. No decryption tools or information on..
|
|
For the past 3 years, Jason Scott (creator of BBS: The Documentary) has been working on another project, telling the history and the legends of text adventure games. 80 interviews later, he comes to DEFCON to show footage, describe the process of making the film, why history of games is important, and what it was like to visit the actual cave the first adventure game was based on. Jason Scott is celebrating 10 years of running his comp..
|
|
Jay Beale: They're Hacking Our Clients! Introducing Free Client-side Intrusion Prevention.
-
www.defcon.org
-
19 years ago
-
eng
In the face of far stronger firewall and IPS-protected perimeters,attackers are compromising far more systems by hacking our web browsers, e-mail clients, and office document tools. Unfortunately,vulnerability assessment practices still focus on checking listening services, even on workstations. Detecting vulnerable clients is left for patch management tools, which aren't in consistent or wide enough use. Even when organizations are able to....
|
|
This talk introduces a new open source, plugin-extensible attack tool for exploiting web applications that use cleartext HTTP, if only to redirect the user to the HTTPS site. We'll demonstrate attacks on online banking as well as Gmail, LinkedIn, LiveJournal and Facebook. We'll also compromise computers and an iPhone by subverting their software installation and update process. We'll inject Javascript into browser sessions and demonstrate C....
|
|
How much data do you generate in the process of living an ordinary day? This talk covers various ways to gather, persist and analyze the data stream that is your life. We'll cover a few of the approaches that are available today, some easy code you can whip up to persist anything you please, and what to expect from the community and businesses moving forward. Privacy/security impact is sure to be huge, so hold on to your hats, and start tra..
|
|
Have you gone to school? Are you going to school? Do you work at a school? How do you prove you went to a particular high school, college or university? FACT: Educational institutions MUST keep your personal/confidential information. Therefore, your personal/confidential information might be at risk! This presentation will be about typical software packages found at educational institutions and their vulnerabilities. We will use known attac....
|
|
We like hardware and we like messing with people. BSODomizer lets us do both. BSODomizer is a small propeller-based electronic device that interfaces between a VGA output device (laptop or desktop) and VGA monitor and will flash images at random time intervals. (Surprise Goatse!) Or display your favorite BSOD causing the confused user to turn off their machine over and over again. Customization for different modes are configurable via on-bo....
|
|
John "Jur1st" Benson: When Lawyers Attack! Dealing with the New Rules of Electronic Discovery
-
www.defcon.org
-
19 years ago
-
eng
The legal community is slowly accepting that the changes to the Federal rules which change the law's approach to electronic evidence are not going away. Vendors are clamoring to sell their e-discovery "solutions" to law firms and corporations alike, often taking advantage of the uncertainty that comes with such sweeping changes to the law. The changes to the Federal Rules change the way in which individuals and organizations approach t....
|
|
Own the VMware box and you get half the servers on the network for free. Although, depending on the VMware server's configuration, whether you want to be stealthy about it and whether you want to avoid any disruption it may not always be quite that simple. During this talk we will take a look at ways of jumping from a server to guest OS without causing any disruption and also some tools for assessing the security posture of VMware products.....
|
|
Jonathan Brossard: Bypassing pre-boot authentication passwords by instrumenting the BIOS keyboard buffer (practical low level attacks against x86 pre-boot authentication software)
-
www.defcon.org
-
19 years ago
-
eng
Pre-boot authentication software, in particular full hard disk encryption software, play a key role in preventing information theft. In this paper, we present a new class of vulnerability affecting multiple high value pre-boot authentication software, including the latest Microsoft disk encryption technology : Microsoft Vista's Bitlocker, with TPM chip enabled. Because Pre-boot authentication software programmers commonly make wrong assumpt....
|
|
Think amateur radio is all about dorks with walkie talkies? Think again. Amateur radio presents one of the last bastions for open radio experimentation. This talk will provide a brief introduction to amateur radio, explain the advantages of licensed spectrum for experimentation, and describe how to get involved in the leading edge of radio hacking. JonM has been a licensed amateur radio operator for nearly a decade, but has never worn ..
|
|
Kevin Figueroa, Marco Figueroa & Anthony Williams: VLANs Layer 2 Attacks: Their Relevance and their Kryptonite
-
www.defcon.org
-
19 years ago
-
eng
Proper network infrastructure configuration is a crucial step in a successful defense in depth strategy for any organization. The fact that the network fabric is susceptible to these attacks years after their initial discovery is alarming and disgusting at the same time. We propose to revisit these attacks using contemporary techniques and tools and also offer equally contemporary solutions to mitigate or foil these malicious networks attac....
|
|
Kolisar: WhiteSpace: A Different Approach to JavaScript Obfuscation
-
www.defcon.org
-
19 years ago
-
eng
A different approach to JavaScript obfuscation will be presented. There are certain telltale indicators within an obfuscated JavaScript file which can be used for detection and protection. These signs occur in almost all obfuscated JavaScript and are easily detected via software and visual inspection. This different approach addresses these telltale indicators and provides a method of JavaScript obfuscation which hides these indicators from....
|
|
Ever since SirDystic's SMBRelay release the weaknesses of the NTLM protocol have been repeatedly shown. For over twenty years this protocol has been refined by Microsoft, it's time to let it go and stop supporting it within our networks. This presentation will trace the history of the NTLM protocol and the various attacks that have befallen it over the past decade, the attempts at fixing them and why these fixes have not succeeded. I w....
|
|
Lee Kushner & Mike Murray: Career Mythbusters-Separating Fact from Fiction in your Information Security Career
-
www.defcon.org
-
19 years ago
-
eng
How long should my resume be? Do I really need to be a Manager? Do I need to attend business school? What certifications do I need? Does my title matter? Should I go after money or a cool job? What are the hot skills du jour? How do I use LinkedIn and Facebook? All of these questions are asked continually by Information Security professionals as they assess their current positions and determine which future opportunities align with their as....
|
|
Luciano Bello & Maximiliano Bertacchini: Predictable RNG in the vulnerable Debian OpenSSL package, the What and the How.
-
www.defcon.org
-
19 years ago
-
eng
Recently, the Debian project announced an OpenSSL package vulnerability which they had been distributing for the last two years. This bug makes the PRNG predictable, affecting the keys generated by openssl and every other system that uses libssl (eg. openssh, openvpn). We will talk about this bug, its discovery and publication, its consequences, and exploitation. As well, we will demonstrate some exploitation tools. Luciano Bello is an..
|
|
I can't tell you how often I'm listening to trance, goa or industrial when I'm coding. Often when we're stuck in a black hole, or just can't figure the problem out - the right music will help. Why does this work? It seems motivating, and it seems like we solve problems easier, and it seems to create a flow. Turns out, your brain is like a tuning fork. This talk will include a bit of biology - going over the basics of the brain structures, n..
|
|
In this confused rant^W^W talk, I will explain why the little green men are right, and also know how to party. I will show you some new toys. Shiny ones. Ones that go 'beep' and have flashy lights. You will like it, and I will be able to return to my home planet, mission accomplished, to the adulation of the triple-breasted masses and the reward of a grateful nation, followed by tea, medals and an inadequate state pension. Or I'll go to jai....
|
|
Marc Weber Tobias & Matt Fiddler: Open in 30 Seconds: Cracking One of the Most Secure Locks in America
-
www.defcon.org
-
19 years ago
-
eng
Many high security lock manufacturers claim that their cylinders are impervious to covert methods of entry including picking, bumping, and decoding and that they offer high levels of key control, effectively preventing the illegal or unauthorized duplication of their keys. New and unique methods to compromise one of the most secure locks in America by forced, covert, and surreptitious entry were developed during an eighteen month research p....
|
|
ModScan is a new tool designed to map a SCADA MODBUS TCP based network. The tool is written in python for portability and can be used on virtually any system with few required libraries. The presentation includes a demonstration of the ModScan scanner as well as a rundown of the various features and modes available. I will also be covering the MODBUS and MODBUS TCP protocols including packet construction and communication flows. A brief SCA....
|
|
As pentesters and hackers we often find the need to create our exploits on the fly. Doing this always presents a challenge. But one challenge took us to a new limit and a new level. We want to share the method with you. From Bug to 0Day will show the audience the process of fuzzing, locating the bug, using egghunters then figuring out to build a pure alphanumeric shellcode to exploit it. This will truly be the most mind bending 60 min....
|
|
Discover the great mystery that is the Emergency Alert System. An elaborate way for the President of the United States to have his or her voice heard from every broadcast outlet at the same time. It can also perform other less important rolls such as letting the public know when their lives may be in danger by several natural occurring and man made events. Matt Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators o..
|
|
Not every bad guy writes down passwords on sticky note by their monitor. Not every system administrator fully documents everything before they leave. There are a lot of legitimate reasons why you might need to crack a password. The problem is most people don't have a supercomputer sitting in their basement or the money to go out and buy a rack of FPGAs. This talk deals with getting the most out of the computing resources you do have when cr....
|
|
Matt Yoder: The Death Envelope: A Medieval Solution to a 21st Century Problem
-
www.defcon.org
-
19 years ago
-
eng
While many aftercare solutions and recommendations cover "average American" needs, none have tackled, full-on, the needs of the rapidly growing high tech segment of the population. As the amount of passwords and other secret "brainspace-only" information grows for many, many, individuals, it becomes obvious that a solution is needed for the dispensation of this information in the event of one's death or extreme disablement. It turns out tha....
|
|
In this talk I will be discussing Exploit Chaining in Web Applications and CSRF. I will discuss the surface area problem in security and how to gain access to a l attack surface using CSRF. I will detail the process I used to find and exploit a vulnerability in a real world application. I will discuss how to have fun in a sandbox and defeating CSRF protection. I will also talk about the defenses against these attacks. I will be releasing an....
|
|
This presentation will detail two methods of breaking captcha. One uses RainbowCrack to break a visual captcha. The other uses fuzzy logic to break an audio captcha. Both methods are 100% effective. These are real attacks that affect real world software: CVE-2008-2020 CVE-2008-2019. Exploit code is available to the public Michael Brooks is a puzzle master. Some people like Sudoku, but Michael likes hacking. Michael is a Computer Scienc....
|
|
Michael Ligh & Greg Sinclair: Malware RCE: Debuggers and Decryptor Development
-
www.defcon.org
-
19 years ago
-
eng
This talk will focus on using a debugger to reverse engineer malware, with an emphasis on building decryption tools for credential recovery and command/control (c&c) inspection. Most modern-day trojans exhibit cryptography, or just home-grown obfuscation techniques, to prevent analysis of the stolen data or c&c protocol. This presentation will show how to script the debugger such that it leverages the trojan's own internal functions to decr....
|
|
Last year during my Tor presentations at Black Hat and Defcon, and in a follow up post on BugTraq, I announced that many SSL secured websites are vulnerable to cookie hijacking by way of content element injection. Unfortunately, my announcement was overshadowed by Robert Graham's passive cookie stealing attacks (aka 'SideJacking'). The difference between our attacks is this: instead of sniffing passively for cookies, it is possible to ....
|
|
Mike Renlund: The Big Picture: Digital Cinema Technology and Security
-
www.defcon.org
-
19 years ago
-
eng
Digital Cinema. Its the first major upgrade to a movie's image in more than 50 years, and it has brought new standards of quality, security, and technology into your local theater complex. This talk will cover what the new BIG PICTURE is all about, the changes made from film, both in the image and sound, and the new security methods involved that help prevent piracy. 3D and alternative content will also be discussed. Come see where the tech..
|
|
Mike Spindel & Scott Torborg: CAPTCHAs: Are they really hopeless? (Yes)
-
www.defcon.org
-
19 years ago
-
eng
CAPTCHAs are widely used to protect websites against malicious robots. Yet, CAPTCHAs are being broken routinely by spammers, malware authors, and other nefarious characters. This talk will review and demonstrate many of the implementation weaknesses that are routinely exploited to break image-based CAPTCHAs, and offer suggestions for improving the effectiveness of CAPTCHAs. Rather than attempt an in-depth examination of any single CAPTCHA o....
|
|
Morgan Marquise-Boire: Fear, Uncertainty and the Digital Armageddon
-
www.defcon.org
-
19 years ago
-
eng
We now live in an age where attacks on critical infrastructure will cause real world harm. An increasing global concern regarding cyber-terrorism reflects the problem critical infrastructure security poses for many large IT consulting companies, telecommunications providers, utilities and industrial companies. SCADA networks are the foundation of the infrastructure which makes everyday life possible in most first world countries. This ....
|