|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Zulla/DEFCON-20-Zulla-Improving-Web-Vulnerability-Scanning.pdf Improving Web Vulnerability Scanning Dan Zulla A new approach for web vulnerability scanning that outbids most existing scanners. Dan Zulla contributed to various open source vulnerability scanning projects and to the security ..
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Viss/DEFCON-20-Viss-SHODAN.pdf Drinking From the Caffeine Firehose We Know as Shodan Viss Information Security Consultant, Gentleman of Fortune Shodan is commonly known for allowing users to search for banners displayed by a short list of services available over the internet. Shodan can quite easil....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Zulla/DEFCON-20-Zulla-Improving-Web-Vulnerability-Scanning.pdf Improving Web Vulnerability Scanning Dan Zulla A new approach for web vulnerability scanning that outbids most existing scanners. Dan Zulla contributed to various open source vulnerability scanning projects and to the security ..
|
|
Chema Alonso and Manu "The Sur"- Owning Bad Guys {And Mafia} With Javascript Botnets
-
www.defcon.org
-
14 years ago
-
eng
Owning Bad Guys {And Mafia} With Javascript Botnets Chema Alonso Security Researcher, Informatica64 Manu "The Sur" Penetration Tester, Informatica64 Man in the middle attacks are still one of the most powerful techniques for owning machines. In this talk MITM schemas in anonymous services are going to be discussed. Then attendees will see how easily a botnet using javascript can be created to analyze that kind of connections and so....
|
|
Anch - The Darknet of Things, Building Sensor Networks That Do Your Bidding
-
www.defcon.org
-
14 years ago
-
eng
The Darknet of Things, Building Sensor Networks That Do Your Bidding Anch Omega The Internet of Things... It is coming, wearing hardware that communicates across the Internet is starting to become a reality, chips are getting smaller, as a society we are connected all the time... Building these devices is easier then we thought, putting them onto a network that is ours... EVEN BETTER! Come experience the Darknet of Things. Learn wh..
|
Extra Materials: https://www.defcon.org/images/defcon-20/dc-20-presentations/Atlas/Extras.zip atlas 0f d00m c0rp0ration Wifi is cool and so is cellular, but the real fun stuff happens below the GHz line. Medical systems, mfg plant/industrial systems, cell phones, power systems, it's all in there! atlas and some friends set out to turn pink girltech toys into power-systems-attack tools. Through several turns and changes, the ....
|
|
Chema Alonso and Manu "The Sur"- Owning Bad Guys {And Mafia} With Javascript Botnets
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets-WP.pdf Owning Bad Guys {And Mafia} With Jav....
|
|
Anch - The Darknet of Things, Building Sensor Networks That Do Your Bidding
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Anch-Omega/DEFCON-20-Anch-Omega-The-Darknet-of-Things.pdf The Darknet of Things, Building Sensor Networks That Do Your Bidding Anch Omega The Internet of Things... It is coming, wearing hardware that communicates across the Internet is starting to become a reality, chips are getting small....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/DEFCON-20-Atlas-Sub-Ghz-or-Bust.pdf Extra Materials: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/Extras.zip atlas 0f d00m c0rp0ration Wifi is cool and so is cellular, but the real fun stuff happens below the GHz line. Medical systems, m....
|
|
Chema Alonso and Manu "The Sur"- Owning Bad Guys {And Mafia} With Javascript Botnets
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets-WP.pdf Owning Bad Guys {And Mafia} With Jav....
|
|
Anch - The Darknet of Things, Building Sensor Networks That Do Your Bidding
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Anch-Omega/DEFCON-20-Anch-Omega-The-Darknet-of-Things.pdf The Darknet of Things, Building Sensor Networks That Do Your Bidding Anch Omega The Internet of Things... It is coming, wearing hardware that communicates across the Internet is starting to become a reality, chips are getting small....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/DEFCON-20-Atlas-Sub-Ghz-or-Bust.pdf Extra Materials: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/Extras.zip atlas 0f d00m c0rp0ration Wifi is cool and so is cellular, but the real fun stuff happens below the GHz line. Medical systems, m....
|
|
Chema Alonso and Manu "The Sur"- Owning Bad Guys {And Mafia} With Javascript Botnets
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets-WP.pdf Owning Bad Guys {And Mafia} With Jav....
|
|
Anch - The Darknet of Things, Building Sensor Networks That Do Your Bidding
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Anch-Omega/DEFCON-20-Anch-Omega-The-Darknet-of-Things.pdf The Darknet of Things, Building Sensor Networks That Do Your Bidding Anch Omega The Internet of Things... It is coming, wearing hardware that communicates across the Internet is starting to become a reality, chips are getting small....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/DEFCON-20-Atlas-Sub-Ghz-or-Bust.pdf Extra Materials: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/Extras.zip atlas 0f d00m c0rp0ration Wifi is cool and so is cellular, but the real fun stuff happens below the GHz line. Medical systems, m....
|
Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, &yet This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identification of blind xss vectors. Think drag and drop exploits post xss vuln identification. For blind xss, xss.io is a callback and hook manager for intel collected by executed and non-execut....
|
|
Branco, Oakley and Bratus - Overwriting the Exception Handling Cache PointerDwarf Oriented Programming
-
www.defcon.org
-
14 years ago
-
eng
Overwriting the Exception Handling Cache PointerDwarf Oriented Programming Rodrigo Rubira Branco Vulnerability & Malware Research Labs, Qualys James Oakley Programmer Sergey Bratus Research Ass't Professor, Comp. Science, Dartmouth College This presentation describes a new technique for abusing the DWARF exception handling architecture used by the GCC tool chain. This technique can be used to exploit vulnerabilities in programs c....
|
Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place of commerce. For decades, hackers and phone phreaks crowded around them as an altar to high technology and a means to "reach out and touch someone". Fast forward to today, most people ha....
|
Hardware Backdooring is Practical Jonathan Brossard Toucan System Whitepaper Available here: https://www.defcon.org/images/defcon-20/dc-20-presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf This presentation will demonstrate that permanent backdooring of hardware is practical. We have built a generic proof of concept malware for the intel architecture, Rakshasa, capable of infecting more than a....
|
DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to come. As with many industries, a DIY approach can yield similar results for much less cost, while creating something truly unique. This talk will explore the possibilities and pr..
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....
|
|
Branco, Oakley and Bratus - Overwriting the Exception Handling Cache PointerDwarf Oriented Programming
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....
|
|
Branco, Oakley and Bratus - Overwriting the Exception Handling Cache PointerDwarf Oriented Programming
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....
|
|
Branco, Oakley and Bratus - Overwriting the Exception Handling Cache PointerDwarf Oriented Programming
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....
|
KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security tools in honor of DEF CON's 20th anniversary?! Jeff Bryner Jeff has toiled for over 20 years integrating systems, performing incident response and forensics and ultimately fixing s..
|
|
Thomas Cannon - Into the Droid: Gaining Access to Android User Data
-
www.defcon.org
-
14 years ago
-
eng
Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers cracking lockscreen passwords, creating custom forensic ramdisks, bypassing bootloader protections and stealth real-time data acquisition. We’ll even cover some crazy techniques - t....
|
|
Chris Conley - Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing
-
www.defcon.org
-
14 years ago
-
eng
Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies build backdoors into their services for law enforcement use have attacted widespread attention and criticism, and rightly so. But DC is far from the only place that officials are making decisio....
|
|
Conti, Shay and Hartzog - Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement
-
www.defcon.org
-
14 years ago
-
eng
Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass't Professor, Cumberland School of Law, Samford University From smart pajamas that monitor our sleep patterns to mandatory black boxes in cars to smart trash carts that divulge recycling violations in ....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Bryner/DEFCON-20-Bryner-KinectASploitv2.pdf KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security to..
|
|
Thomas Cannon - Into the Droid: Gaining Access to Android User Data
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Cannon/DEFCON-20-Cannon-Into-The-Droid.pdf Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers....
|
|
Chris Conley - Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conley/DEFCON-20-DEF-CON-Conley-Bad-Tech-Policy.pdf Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies buil....
|
|
Conti, Shay and Hartzog - Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement
-
www.defcon.org
-
14 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conti-Shay-Hartzog/DEFCON-20-Conti-Shay-Hartzog-SkinnerBox.pdf Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass'....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Bryner/DEFCON-20-Bryner-KinectASploitv2.pdf KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security to..
|