|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Jon Oberheide - Antique Exploitation (aka Terminator 3.1.1 for Workgroups)
-
www.defcon.org
-
15 years ago
-
eng
Just as the Terminator travels back from the future to assassinate John Connor using futuristic weaponry, we will travel a couple decades back in time to attack a computing platform that threatens the future of Skynet: Windows 3.11 for Workgroups! Come enjoy the hilarity that ensues when applying modern attack tools and exploitation techniques to an operating system that is approaching its 20th birthday yet EOL'ed only two years ago. We'll ..
|
|
Jonathan Lee & Neil Pahl - Bypassing Smart-Card Authentication and Blocking Debiting: Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems
-
www.defcon.org
-
15 years ago
-
eng
Atmel CryptoMemory based smart cards are deemed to be some of the most secure on the market, boasting a proprietary 64-bit mutual authentication protocol, attempts counter, encrypted checksums, anti-tearing counter measures, and more. Yet none of these features are useful when the system implementation is flawed. Communications were sniffed, protocols were analyzed, configuration memory was dumped, and an elegant hardware man-in-the-mi..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Joseph McCray - You Spent All That Money and You Still Got Owned…
-
www.defcon.org
-
15 years ago
-
eng
This talk will focus on practical methods of identifying and bypassing enterprise class security solutions such as Load Balancers, both Network and Host-based Intrusion Prevention Systems (IPSs), Managed Anti-Virus, Web Application Firewalls (WAFs), and Network Access Control Solutions (NAC). Joe has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, f..
|
|
Josh Pyorre & Chris McKenney - Build Your Own Security Operations Center for Little or No Money
-
www.defcon.org
-
15 years ago
-
eng
In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....
|
|
Joshua Marpet - Facial Recognition: Facts, Fiction; and Fcsk-Ups!
-
www.defcon.org
-
15 years ago
-
eng
Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....
|
|
Josh Pyorre & Chris McKenney - Build Your Own Security Operations Center for Little or No Money
-
www.defcon.org
-
15 years ago
-
eng
In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....
|
|
Joshua Marpet - Facial Recognition: Facts, Fiction; and Fcsk-Ups!
-
www.defcon.org
-
15 years ago
-
eng
Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....
|
|
Josh Pyorre & Chris McKenney - Build Your Own Security Operations Center for Little or No Money
-
www.defcon.org
-
15 years ago
-
eng
In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....
|
|
Joshua Marpet - Facial Recognition: Facts, Fiction; and Fcsk-Ups!
-
www.defcon.org
-
15 years ago
-
eng
Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....
|
|
Joshua Wise - From "No Way" to 0-day: Weaponizing the Unweaponizable
-
www.defcon.org
-
15 years ago
-
eng
Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....
|
|
Joshua Wise - From "No Way" to 0-day: Weaponizing the Unweaponizable
-
www.defcon.org
-
15 years ago
-
eng
Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....
|
|
Joshua Wise - From "No Way" to 0-day: Weaponizing the Unweaponizable
-
www.defcon.org
-
15 years ago
-
eng
Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....
|
|
Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..
|
|
Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..
|
|
Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..
|
|
Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..
|
|
Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..
|
|
Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..
|
|
Justin Morehouse & Tony Flick - Getting Social with the Smart Grid
-
www.defcon.org
-
15 years ago
-
eng
Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....
|
|
Justin Morehouse & Tony Flick - Getting Social with the Smart Grid
-
www.defcon.org
-
15 years ago
-
eng
Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....
|
|
Justin Morehouse & Tony Flick - Getting Social with the Smart Grid
-
www.defcon.org
-
15 years ago
-
eng
Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....
|
|
In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....
|
|
Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....
|
|
In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....
|
|
Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....
|
|
In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....
|
|
Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....
|
|
Kevin Mahaffey & John Hering - App Attack: Surviving the Mobile Application Explosion
-
www.defcon.org
-
15 years ago
-
eng
The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....
|
|
Kevin Mahaffey & John Hering - App Attack: Surviving the Mobile Application Explosion
-
www.defcon.org
-
15 years ago
-
eng
The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....
|
|
Kevin Mahaffey & John Hering - App Attack: Surviving the Mobile Application Explosion
-
www.defcon.org
-
15 years ago
-
eng
The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....
|
|
Leigh Honeywell & follower - Physical Computing, Virtual Security: Adding the Arduino Microcontroller Development Environment to Your Security Toolbox
-
www.defcon.org
-
15 years ago
-
eng
The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....
|
|
Leigh Honeywell & follower - Physical Computing, Virtual Security: Adding the Arduino Microcontroller Development Environment to Your Security Toolbox
-
www.defcon.org
-
15 years ago
-
eng
The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....
|
|
Leigh Honeywell & follower - Physical Computing, Virtual Security: Adding the Arduino Microcontroller Development Environment to Your Security Toolbox
-
www.defcon.org
-
15 years ago
-
eng
The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....
|
|
Luiz "effffn" Eduardo - Your Boss is a Douchebag... How About You?
-
www.defcon.org
-
15 years ago
-
eng
These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....
|
|
Mage2 - Electronic Weaponry or How to Rule the World While Shopping at Radio Shack
-
www.defcon.org
-
15 years ago
-
eng
These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....
|
|
Luiz "effffn" Eduardo - Your Boss is a Douchebag... How About You?
-
www.defcon.org
-
15 years ago
-
eng
These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....
|
|
Mage2 - Electronic Weaponry or How to Rule the World While Shopping at Radio Shack
-
www.defcon.org
-
15 years ago
-
eng
These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....
|
|
Luiz "effffn" Eduardo - Your Boss is a Douchebag... How About You?
-
www.defcon.org
-
15 years ago
-
eng
These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....
|