|
Another year, another batch of packet related stunts. A preview: A Temporal Attack against IP It is commonly said that IP is a stateless protocol. This is not entirely true. We will discuss a mechanism by which IP's limited stateful mechanisms can be exploited to fingerprint operating systems and to evade most intrusion detection systems. Application-layer attacks against MD5 We will show how web pages and other executable environme....
|
|
Another year, another batch of packet related stunts. A preview: A Temporal Attack against IP It is commonly said that IP is a stateless protocol. This is not entirely true. We will discuss a mechanism by which IP's limited stateful mechanisms can be exploited to fingerprint operating systems and to evade most intrusion detection systems. Application-layer attacks against MD5 We will show how web pages and other executable environme....
|
|
Dr. Linton Wells II, Assistant Secretary of Defense for Networks and Information Integration / CIO Dr. Linton Wells, II was named Principal Deputy Assistant Secretary of Defense for Command, Control, Communications and Intelligence (C3I) on August 20, 1998, and serves in that capacity in the C3I successor organization, Networks and Information Integration (NII). In addition, Dr. Wells serves as Acting Deputy Assistant Secretary of Defe....
|
|
Dr. Linton Wells II, Assistant Secretary of Defense for Networks and Information Integration / CIO Dr. Linton Wells, II was named Principal Deputy Assistant Secretary of Defense for Command, Control, Communications and Intelligence (C3I) on August 20, 1998, and serves in that capacity in the C3I successor organization, Networks and Information Integration (NII). In addition, Dr. Wells serves as Acting Deputy Assistant Secretary of Defe....
|
|
While many security practitioners use Nmap, few understand its full power. Nmap deserves part of the blame for being too helpful. A simple command such as "nmap scanme.insecure.org" leaves Nmap to choose the scan type, timing details, target ports, output format, source ports and addresses, and more. You can even specify -iR (random input) and let Nmap choose the targets! Hiding all of these details makes Nmap easy to use, but also easy to ....
|
|
While many security practitioners use Nmap, few understand its full power. Nmap deserves part of the blame for being too helpful. A simple command such as "nmap scanme.insecure.org" leaves Nmap to choose the scan type, timing details, target ports, output format, source ports and addresses, and more. You can even specify -iR (random input) and let Nmap choose the targets! Hiding all of these details makes Nmap easy to use, but also easy to ....
|
|
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
Wesley Tanner and Nick Lane-Smith: End-to-End Voice Encryption over GSM: A Different Approach
-
www.defcon.org
-
13 years ago
-
eng
Where is end-to-end voice privacy over cellular? What efforts are underway to bring this necessity to the consumer? This discussion will distill for you the options available today, and focus on current research directions in technologies for the near future. Cellular encryption products today make use of either circuit switched data (CSD), or high latency packet switched networks. We will discuss the advantages and disadvantages of....
|
|
Wesley Tanner and Nick Lane-Smith: End-to-End Voice Encryption over GSM: A Different Approach
-
www.defcon.org
-
13 years ago
-
eng
Where is end-to-end voice privacy over cellular? What efforts are underway to bring this necessity to the consumer? This discussion will distill for you the options available today, and focus on current research directions in technologies for the near future. Cellular encryption products today make use of either circuit switched data (CSD), or high latency packet switched networks. We will discuss the advantages and disadvantages of....
|
|
Robert E. Lee & Jack C. Louis:Introducing Unicornscan - Riding the Unicorn
-
www.defcon.org
-
13 years ago
-
eng
Unicornscan is an open source (GPL) tool designed to assist with information gathering and security auditing. This talk will contrast the real world problems we've experienced using other tools and methods while demonstrating the solutions that Unicornscan can provide. We will use Unicornscan to collect information from large networks, data mine the collected information, and test systems for susceptibility to specific vulnerabilities.....
|
|
Robert E. Lee & Jack C. Louis:Introducing Unicornscan - Riding the Unicorn
-
www.defcon.org
-
13 years ago
-
eng
Unicornscan is an open source (GPL) tool designed to assist with information gathering and security auditing. This talk will contrast the real world problems we've experienced using other tools and methods while demonstrating the solutions that Unicornscan can provide. We will use Unicornscan to collect information from large networks, data mine the collected information, and test systems for susceptibility to specific vulnerabilities.....
|
|
This presentation describes the possibilities of steganographically embedding information in the "noise" created by automatic translation of natural language documents. An automated natural language translation system is ideal for steganographic applications, since natural language translation leaves plenty of room for variation. Also, because there are frequent errors in legitimate automatic text translations, additional errors inserted by....
|
|
This presentation describes the possibilities of steganographically embedding information in the "noise" created by automatic translation of natural language documents. An automated natural language translation system is ideal for steganographic applications, since natural language translation leaves plenty of room for variation. Also, because there are frequent errors in legitimate automatic text translations, additional errors inserted by....
|
|
Ofir Arkin, A New Hybrid Approach for Infrastructure Discovery, Monitoring and Control
-
www.defcon.org
-
13 years ago
-
eng
An enterprise IT infrastructure is a complex and a dynamic environment that is generally described as a black hole by its IT managers. The knowledge about an enterprise network's layout (topology), resources (availability and usage), elements residing on the network (devices, applications, their properties and the interdependencies among them) as well as the ability to maintain this knowledge up-to-date, are all of critical for managing a....
|
|
Ofir Arkin, A New Hybrid Approach for Infrastructure Discovery, Monitoring and Control
-
www.defcon.org
-
13 years ago
-
eng
An enterprise IT infrastructure is a complex and a dynamic environment that is generally described as a black hole by its IT managers. The knowledge about an enterprise network's layout (topology), resources (availability and usage), elements residing on the network (devices, applications, their properties and the interdependencies among them) as well as the ability to maintain this knowledge up-to-date, are all of critical for managing a....
|
|
Ofir Arkin, On the Current State of Remote Active OS Fingerprinting
-
www.defcon.org
-
13 years ago
-
eng
Active operating system fingerprinting is a technology, which uses stimulus (sends packets) in order to provoke a reaction from network elements. The implementations of active scanning will monitor the network for a response to be, or not, received from probed targeted network elements, and according to the type of response, and the conclusions following (part of an implementation"s intelligence), knowledge will be gathered about the underl....
|
|
Ofir Arkin, On the Current State of Remote Active OS Fingerprinting
-
www.defcon.org
-
13 years ago
-
eng
Active operating system fingerprinting is a technology, which uses stimulus (sends packets) in order to provoke a reaction from network elements. The implementations of active scanning will monitor the network for a response to be, or not, received from probed targeted network elements, and according to the type of response, and the conclusions following (part of an implementation"s intelligence), knowledge will be gathered about the underl....
|
|
Bastille has been re-released as an assessment and hardening tool. With the help of the US Government's TSWG, we've added full hardening assessment capabilities, complete with scoring. This allows Bastille to measure and score an individual system's security settings against user-provided guidelines, possibly before allowing a system onto the network. Security or system administrators can use this to assess the relative state of a given sys....
|
|
Bastille has been re-released as an assessment and hardening tool. With the help of the US Government's TSWG, we've added full hardening assessment capabilities, complete with scoring. This allows Bastille to measure and score an individual system's security settings against user-provided guidelines, possibly before allowing a system onto the network. Security or system administrators can use this to assess the relative state of a given sys....
|
|
Marshall Beddoe, Reverse Engineering Network Protocols using Bioinformatics
-
www.defcon.org
-
13 years ago
-
eng
Network protocol analysis is currently performed by hand using only intuition and a protocol analyzer tool such as tcpdump or Ethereal. This talk presents Protocol Informatics, a method for automating network protocol reverse engineering by utilizing algorithms found in the bioinformatics field. In order to determine fields in protocol packets, samples are aligned using multiple string alignment algorithms and their consensus sequences are ..
|
|
Marshall Beddoe, Reverse Engineering Network Protocols using Bioinformatics
-
www.defcon.org
-
13 years ago
-
eng
Network protocol analysis is currently performed by hand using only intuition and a protocol analyzer tool such as tcpdump or Ethereal. This talk presents Protocol Informatics, a method for automating network protocol reverse engineering by utilizing algorithms found in the bioinformatics field. In order to determine fields in protocol packets, samples are aligned using multiple string alignment algorithms and their consensus sequences are ..
|
|
Daniel Burroughs, Development of An Undergraduate Security Program
-
www.defcon.org
-
13 years ago
-
eng
At the University of Central Florida, an undergraduate program in security is currently being developed. This program will offer students a bachelor's degree through the College of Engineering. It is intended to be an interdisciplinary degree combining coursework from the School of Engineering and Computer Science, College of Health and Public Affairs, and the National Center for Forensic Studies. The purpose of this talk is to present....
|
|
Wes Brown & Scott Dunlop, Mosquito - Secure Remote Code Execution Framework
-
www.defcon.org
-
13 years ago
-
eng
Mosquito is a lightweight framework to deploy and run code remotely and securely in the context of penetration tests. It makes a best effort to ensure that the communications are secure. Special care is taken to ensure that deployed code is not stored outside of process memory space, making it difficult for an eavesdropper to obtain the code. It protects the confidentiality and trade secrets of code that is deployed and run on the target, w....
|
|
Daniel Burroughs, Development of An Undergraduate Security Program
-
www.defcon.org
-
13 years ago
-
eng
At the University of Central Florida, an undergraduate program in security is currently being developed. This program will offer students a bachelor's degree through the College of Engineering. It is intended to be an interdisciplinary degree combining coursework from the School of Engineering and Computer Science, College of Health and Public Affairs, and the National Center for Forensic Studies. The purpose of this talk is to present....
|
|
Wes Brown & Scott Dunlop, Mosquito - Secure Remote Code Execution Framework
-
www.defcon.org
-
13 years ago
-
eng
Mosquito is a lightweight framework to deploy and run code remotely and securely in the context of penetration tests. It makes a best effort to ensure that the communications are secure. Special care is taken to ensure that deployed code is not stored outside of process memory space, making it difficult for an eavesdropper to obtain the code. It protects the confidentiality and trade secrets of code that is deployed and run on the target, w....
|
|
Daniel Burroughs, Auto-adapting Stealth Communication Channels
-
www.defcon.org
-
13 years ago
-
eng
Intrusion detection systems and firewalls generally follow one of two methods of attack detection, signature or anomaly. Signature detection detects known attacks and anomaly detection covers unusual activity (with the hope that it will discover new attacks). Often what is detected by the IDS or firewall is not the original attack, but rather the communication that occurs afterwards. Known methods are easily picked up by signature detect....
|
|
Daniel Burroughs, Auto-adapting Stealth Communication Channels
-
www.defcon.org
-
13 years ago
-
eng
Intrusion detection systems and firewalls generally follow one of two methods of attack detection, signature or anomaly. Signature detection detects known attacks and anomaly detection covers unusual activity (with the hope that it will discover new attacks). Often what is detected by the IDS or firewall is not the original attack, but rather the communication that occurs afterwards. Known methods are easily picked up by signature detect....
|
|
Strom Carlson & Black Ratchet, Be Your Own Telephone Company... With Asterisk
-
www.defcon.org
-
13 years ago
-
eng
Since the invention of the step-by-step switching office by Almon B. Strowger in 1889, telephone switching technology has constantly become more efficient, more complex and easier to manage. Today, anyone with a computer, a telephone and some spare time can assemble a homebrew telephone switching system and become their own miniature telephone company with the aid of a program called Asterisk. This presentation will give a brief overvi....
|
|
Strom Carlson & Black Ratchet, Be Your Own Telephone Company... With Asterisk
-
www.defcon.org
-
13 years ago
-
eng
Since the invention of the step-by-step switching office by Almon B. Strowger in 1889, telephone switching technology has constantly become more efficient, more complex and easier to manage. Today, anyone with a computer, a telephone and some spare time can assemble a homebrew telephone switching system and become their own miniature telephone company with the aid of a program called Asterisk. This presentation will give a brief overvi....
|
|
Ian Clarke & Oskar Sandberg, Routing in the Dark: Scalable Searches in Dark P2P Networks
-
www.defcon.org
-
13 years ago
-
eng
Ian Clarke, Project Coordinator, FreenetProject Inc. Oskar Sandberg, Department of Mathematical Sciences, Chalmers Technical University, Sweden With peer to peer networks under fire by organizations using the legal system to attack participants, it seems that the only sustainable future is for dark, encrypted, networks where participants only talk to peers that they know and trust. Such networks, like WASTE, already exist to some ext....
|
|
Ian Clarke & Oskar Sandberg, Routing in the Dark: Scalable Searches in Dark P2P Networks
-
www.defcon.org
-
13 years ago
-
eng
Ian Clarke, Project Coordinator, FreenetProject Inc. Oskar Sandberg, Department of Mathematical Sciences, Chalmers Technical University, Sweden With peer to peer networks under fire by organizations using the legal system to attack participants, it seems that the only sustainable future is for dark, encrypted, networks where participants only talk to peers that they know and trust. Such networks, like WASTE, already exist to some ext....
|
|
We are besieged with information every day, our inboxes overflow with spam and our search queries return a great deal of irrelevant information. In most cases there is no malicious intent, just simply too much information. However, if we consider active malicious entities, the picture darkens. Denial of information (DoI) attacks assail the human through their computer system and manifest themselves as attacks that target the human's percept....
|
|
We are besieged with information every day, our inboxes overflow with spam and our search queries return a great deal of irrelevant information. In most cases there is no malicious intent, just simply too much information. However, if we consider active malicious entities, the picture darkens. Denial of information (DoI) attacks assail the human through their computer system and manifest themselves as attacks that target the human's percept....
|
|
The Dark Tangent, founder of DEF CON, invites Chief Information Security Officers from global corporations to join him on stage for a unique set of questions and answers. What do CISOs think of David Litchfield, Dan Kaminsky, Joe Grand, Metasploit, Black Hat, and DEF CON? How many years before deperimeterization is a reality? Is security research more helpful or harmful to the economy? What privacy practices do CISOs personally use These qu....
|
|
The Dark Tangent, founder of DEF CON, invites Chief Information Security Officers from global corporations to join him on stage for a unique set of questions and answers. What do CISOs think of David Litchfield, Dan Kaminsky, Joe Grand, Metasploit, Black Hat, and DEF CON? How many years before deperimeterization is a reality? Is security research more helpful or harmful to the economy? What privacy practices do CISOs personally use These qu....
|
|
Deviant Ollam, Introduction to Lockpicking and Physical Security
-
www.defcon.org
-
13 years ago
-
eng
Physical security isn't just a concern of the IT world. Besides securing server rooms, locks of all sizes and styles are scattered throughout our lives. However, much of the general public is unaware of the insecurities present in many lock designs. Through discussion and direct example, Deviant Ollam will address the strengths and weaknesses of standard pin tumbler locks, combination locks, warded locks, wafer locks, and more. Discussion o....
|
|
Deviant Ollam, Introduction to Lockpicking and Physical Security
-
www.defcon.org
-
13 years ago
-
eng
Physical security isn't just a concern of the IT world. Besides securing server rooms, locks of all sizes and styles are scattered throughout our lives. However, much of the general public is unaware of the insecurities present in many lock designs. Through discussion and direct example, Deviant Ollam will address the strengths and weaknesses of standard pin tumbler locks, combination locks, warded locks, wafer locks, and more. Discussion o....
|
|
Kristofer Erickson, The Power to Map: How Cyberspace Is Imagined Through Cartography
-
www.defcon.org
-
13 years ago
-
eng
An ongoing project for scholars in Geography has been to explore how power and cartography are mutually implicated. Geographers have traditionally been concerned with making maps of the earth, but until recently we have seldom reflected on how particular forms of knowledge and power are privileged in the production of maps, and how those maps themselves produce particular geographic imaginations. As new virtual spaces are opened up through ....
|
|
Have you ever been pulled over by the Cops? Do you worry about your home being searched by the Feds? The Hacker's Guide to Search and Arrest is presented in a down and dirty fast pace. You won't hear a single boring case citation here. Instead you get information you can use in every day life, presented in a way that won't make your eyes gaze over. Learn when the Government can legally perform searches or make arrests. Find out what you ca..
|
|
Kristofer Erickson, The Power to Map: How Cyberspace Is Imagined Through Cartography
-
www.defcon.org
-
13 years ago
-
eng
An ongoing project for scholars in Geography has been to explore how power and cartography are mutually implicated. Geographers have traditionally been concerned with making maps of the earth, but until recently we have seldom reflected on how particular forms of knowledge and power are privileged in the production of maps, and how those maps themselves produce particular geographic imaginations. As new virtual spaces are opened up through ....
|
|
Have you ever been pulled over by the Cops? Do you worry about your home being searched by the Feds? The Hacker's Guide to Search and Arrest is presented in a down and dirty fast pace. You won't hear a single boring case citation here. Instead you get information you can use in every day life, presented in a way that won't make your eyes gaze over. Learn when the Government can legally perform searches or make arrests. Find out what you ca..
|
|
Leonard Gallion, A Safecracking Double Feature: Dial "B" For BackDialing and Spike the Wonder Safe
-
www.defcon.org
-
13 years ago
-
eng
This presentation will introduce two powerful, non-destructive safe opening techniques. The first "Dial B For BackDialing," will trace the history of back dialing all the way from Richard Feynman working on the atomic bomb (and opening safes) in the 1940's, to today. This presentation will show how mechanical safes have changed since Feynman's time, but how most are still vulnerable to both his method and the simpler Nascar(tm) technique. T....
|
|
Leonard Gallion, A Safecracking Double Feature: Dial "B" For BackDialing and Spike the Wonder Safe
-
www.defcon.org
-
13 years ago
-
eng
This presentation will introduce two powerful, non-destructive safe opening techniques. The first "Dial B For BackDialing," will trace the history of back dialing all the way from Richard Feynman working on the atomic bomb (and opening safes) in the 1940's, to today. This presentation will show how mechanical safes have changed since Feynman's time, but how most are still vulnerable to both his method and the simpler Nascar(tm) technique. T....
|