|
From almost a week ago, midway through my Christmas vacation, Betaworks announced the latest in a slew of great improvements to the Instapaper platform: Instapaper Daily. Although I cannot say it will replace Tweetbot or Reeder as one of my primary sources for news and articles to read, I really like this as a service and as an indicator of the direction Betaworks plans on taking Instapaper. In the past I have criticized Betaworks for bot..
|
|
As soon as Information Architects released Writer Pro shortly before Christmas, I began collecting “ first look ” pieces after their phenomenal introductory video nearly caused me to shell out a hefty $40 to have the app on both my Mac and iOS devices sight on seen. Much more cautions after my poor experience with Coin though, I exercised a bit of restraint in choosing to wait until after Christmas to make my final decision. Nine days..
|
|
Brandon Wiley - Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine
-
media.defcon.org
-
12 years ago
-
eng
Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine BRANDON WILEY RESEARCHER, STEP THREE: PROFIT! The greatest danger to free speech on the Internet today is filtering of traffic using protocol fingerprinting. Protocols such as SSL, Tor, BitTorrent, and VPNs are being summarily blocked, regardless of their legal and ethical uses. Fortunately, it is possible to bypass this filtering by reencoding traffic into a form ....
|
LosT Welcomes the DEF CON Attendees, discusses the making of the DEF CON 21 Badges, and the badge hacking contest.
|
|
Panel - Home Invasion 2.0 - Attacking Network-Controlled Consumer Devices
-
media.defcon.org
-
12 years ago
-
eng
Home Invasion 2.0 - Attacking Network-Controlled Consumer Devices DANIEL "UNICORNFURNACE" CROWLEY MANAGING CONSULTANT, SPIDERLABS, TRUSTWAVE JENNIFER "SAVAGEJEN" SAVAGE SOFTWARE ENGINEER DAVID "VIDEOMAN" BRYAN A growing trend in electronics is to have them integrate with your home network in order to provide potentially useful features like automatic updates or to extend the usefulness of existing technologies such as door locks you....
|
DEF CON is proud to announce the 3rd annual DEF CON awards ceremony, renamed the DC Recognize Awards. These awards are given to deserving individuals in the community, industry, and media. Your hosts again this year will be Jericho, Jeff Moss, and Russ Rogers.
|
Evolving Exploits Through Genetic Algorithms SOEN HACKER FOR TEAM VANNED This talk will discuss the next logical step from dumb fuzzing to breeding exploits via machine learning & evolution. Using genetic algorithms, this talk will take simple SQL exploits and breed them into precision tactical weapons. Stop looking at SQL error messages and carefully crafting injections, let genetic algorithms take over and create lethal exploits to PW..
|
|
Teal Rogers and Alejandro Caceres - The dawn of Web 3.0: website mapping and vulnerability scanning in 3D, just like you saw in the movies
-
media.defcon.org
-
12 years ago
-
eng
The dawn of Web 3.0: website mapping and vulnerability scanning in 3D, just like you saw in the movies TEAL ROGERS TRINARY SOFTWARE, OWNER ALEJANDRO CACERES OWNER, HYPERION GRAY, LLC Remember that scene in Hackers where Jonny Lee Miller and Angelina Jolie get a bunch of hackers to attack Fisher Steven's network through vulnerabilities that they find while flying (literally) through Fisher's network? Even though it had no basis in real....
|
The Dark Tangent and GOONS bring the conference to a close, announce contest winners, and hand out prizes.
|
Prowling Peer-to-Peer Botnets After Dark TILLMANN WERNER CROWDSTRIKE, INC. Peer-to-peer botnets have become the backbone of the cybercrime ecosystem. Due to their distributed nature, they are more difficult to understand and contain than traditional botnets. To combat this problem, we have developed the open-source framework *prowler* for peer-to-peer botnet tracking and node enumeration. It combines efficient crawling strategies with t....
|
Made Open: Hacking Capitalism TODD BONNEWELL MAN WITH A MESSAGE, MADEOPEN.COM The game is Capitalism. The rule makers are the banks, corporations and governments. This presentation is about playing a game that is rigged by the rule makers, and winning in such fashion that the game is never the same. If you like breaking things and building them back up, or are a person, please at least watch this at a later time. I forgive you for no..
|
|
Todd Manning and Zach Lanier - GoPro or GTFO: A Tale of Reversing an Embedded System
-
media.defcon.org
-
12 years ago
-
eng
GoPro or GTFO: A Tale of Reversing an Embedded System TODD MANNING SENIOR RESEARCH CONSULTANT, ACCUVANT LABS ZACH LANIER SENIOR RESEARCH CONSULTANT, ACCUVANT LABS Embedded systems are shrinking in size and becoming widely used in many consumer devices. High quality optic sensors and lenses are also shrinking in size. The GoPro Hero 3 camera leverages high quality camera equipment with multiple embedded operating systems to offer no....
|
De-Anonymizing Alt.Anonymous.Messages TOM RITTER In recent years, new encryption programs like Tor, RedPhone, TextSecure, Cryptocat, and others have taken the spotlight - but the old guard of remailers and shared inboxes are still around. Alt.Anonymous.Messages is a stream of thousands of anonymous, encrypted messages, seemingly opaque to investigators. For the truly paranoid, there is no communication system that has better anonymity ....
|
|
Tom Steele and Dan Kottmann - Collaborative Penetration Testing With Lair
-
media.defcon.org
-
12 years ago
-
eng
Collaborative Penetration Testing With Lair TOM STEELE SENIOR SECURITY CONSULTANT, FISHNET SECURITY DAN KOTTMANN SECURITY CONSULTANT, FISHNET SECURITY Lair is an open-source project developed for and by pentesters. Built on Meteor and Node.js with a dash of Python, Lair is a web application that normalizes, centralizes, and manages diverse test data from a number of common tools including Nmap, Nessus, Nexpose, and Burp. Unlike existi....
|
|
Tony Mui and Wai-Leng Lee - Kill 'em All — DDoS Protection Total Annihilation!
-
media.defcon.org
-
12 years ago
-
eng
Kill 'em All — DDoS Protection Total Annihilation! TONY MIU TECHNICAL DIRECTOR, BLOODSPEAR RESEARCH GROUP WAI-LENG LEE VP OF ENGINEERING, BLOODSPEAR RESEARCH GROUP With the advent of paid DDoS protection in the forms of CleanPipe, CDN / Cloud or whatnot, the sitting ducks have stood up and donned armors... or so they think! We're here to rip apart this false sense of security by dissecting each and every mitigation techniques you can ....
|
HTTP Time Bandit VAAGN TOUKHARIAN PRINCIPAL ENGINEER, QUALYS TIGRAN GEVORGYAN ENGINEERING MANAGER, QUALYS While web applications have become richer to provide a higher level user experience, they run increasingly large amounts of code on both the server and client sides. A few of the pages on the web server may be performance bottlenecks. Identifying those pages gives both application owners as well as potential attackers the chance t....
|
|
Wesley McGrew - Pwn The Pwn Plug: Analyzing and Counter-Attacking Attacker-Implanted Devices
-
media.defcon.org
-
12 years ago
-
eng
Pwn The Pwn Plug: Analyzing and Counter-Attacking Attacker-Implanted Devices WESLEY MCGREW RESEARCH ASSOCIATE, MISSISSIPPI STATE UNIVERSITY Malicious attackers and penetration testers alike are drawn to the ease and convenience of small, disguise-able attacker-controlled devices that can be implanted physically in a target organization. When such devices are discovered in an organization, that organization may wish to perform a forensic....
|
|
Zak Blacher - Transcending Cloud Limitations by Obtaining Inner Piece
-
media.defcon.org
-
12 years ago
-
eng
Transcending Cloud Limitations by Obtaining Inner Piece ZAK BLACHER With the abundance of cloud storage providers competing for your data, some have taken to offering services in addition to free storage. This presentation demonstrates the ability to gain unlimited cloud storage by abusing an overlooked feature of some of these services. Zak Blacher is currently pursuing a Masters of Mathematics in Computer Science, and expects to be..
|
Hacking Driverless Vehicles ZOZ CANNYTROPHIC DESIGN Are driverless vehicles ripe for the hacking? Autonomous and unmanned systems are already patrolling our skies and oceans and being tested on our streets and highways. All trends indicate these systems are at an inflection point that will show them rapidly becoming commonplace. It is therefore a salient time for a discussion of the capabilities and potential vulnerabilities of these sy....
|
|
Many web developers know about SSL, but it is very common to see it only partially deployed, or not deployed where it should be. This basic guide on when and how to deploy SSL will help you avoid the most common mistakes. via A basic guide to when and how to deploy HTTPS — Erik Romijn.
|
|
On seeing WarGames for the first time in the 1980s, I wondered which magazine it was. Later, after seeing it on TV and on VHS/DVD, the same question kept nagging at me. I believed that I would one day get to the bottom of this matter. I correctly assumed that the magazine was a real world magazine with a fake advertisement added to it. Through some effort and persistence I finally achieved my goal on 2013-02-24 at 5:30pm.
|
|
Fred Brooks wrote the software development classic The Mythical Man-Month almost 40 years ago. In this interview, Brooks explains why managers still make the same mistakes. via Why Good Programming Projects Go Bad.
|
|
If you write Python code, switching to IPython is the number one thing you can do to immediately improve your productivity. Bold words, I know. Let’s look at how IPython can make you a more productive programmer. via You Should Change Your Python Shell | GrokCode.
|
|
Book Review: Debian 7: System Administration Best Practices
-
thomashunter.name
-
12 years ago
-
eng
|
|
If you write Python code, switching to IPython is the number one thing you can do to immediately improve your productivity. Bold words, I know. Let’s look at how IPython can make you a more productive programmer. via You Should Change Your Python Shell | GrokCode.
|
|
Many web developers know about SSL, but it is very common to see it only partially deployed, or not deployed where it should be. This basic guide on when and how to deploy SSL will help you avoid the most common mistakes. via A basic guide to when and how to deploy HTTPS — Erik Romijn.
|
|
If you follow me on Twitter you likely would’ve seen my photos of a silly looking contraption with tiny wheels. Meet Deider, the Brompton folding bike:
|
|
Octopress and S3 I’ve finally moved this site over to Octopress and S3. There is a lot of work to be done, the most pressing of which is fixing leftover broken images, implementing code highlighting, and fixing some theme stuff (like the navigation links), but other than that it’s going ok. The move overall was pretty hassle-free with no real problems. I ended up with the following setup:
|
|
How has your experience been relating to the use of a bluetooth keyboard with the iPad; specifically with the way iOS requires the activation of Voiceover to increase remote keyboard functionality. Personally I find the accessibility features in iOS second to non both keyboard and voice but wanted to pole for your experience and findings as I and I’m sure others may be interested to learn such things. Frustratingly how to copy and paste code outside of anything but screen or TMUX. Thanks (:
-
yieldthought.com
-
12 years ago
-
eng
Hi Edg3e, I hadn't looked into using Voiceover to activate app switching and so on - that's... interesting. It takes away one of the few things I preferred about the Surface, whilst adding some of its own new annoyances. Progress, I guess? I sympathize with the copy and paste - often I wanted to take some text from the console and put it into a bug ticket; I ended up writing a small script that uses our bug tracker's API to add a comment ....
|
|
Learn how to inspect view hierarchies of third-party iOS apps using a jailbroken device and debugging tools like Reveal for design insights.
|
|
A little more than a year ago , I was, as someone looking for .Net developers that knew the SharePoint API, frustrated by the confusion in the SharePoint space between the different kinds of developers that exist in the ecosystem. This confusion persists to this day, much to the detriment of
|
|
Samuel Hulick is a user experience designer and runs useronboard.com. He is currently writing a book called User Onboarding.
|
A little over a year ago I wrote a post about using Beyond Compare on Mac via Wine. A native version is now in beta and open to everyone! If you haven't tried Beyond Compare, I suggest you do. If you have you already know how awesome it is. I've been testing the Alpha for many months now and thought I'd throw together some instructions for getting it going with git. You can download the beta here: http://www.scootersoftware.com/beta....
|
A little over a year ago I wrote a post about using Beyond Compare on Mac via Wine. A native version is now in beta and open to everyone! If you haven't tried Beyond Compare, I suggest you do. If you have you already know how awesome it is. I've been testing the Alpha for many months now and thought I'd throw together some instructions for getting it going with git. You can download the beta here: http://www.scootersoftware.com/beta....
|
|
I think that turbolinks is great: it makes it easy to add AJAX PushState to your Rails Applications. The only problem with that is that we can’t use it any WEB application, because it’s a Ruby Gem. So I did some ugly-but-easy hacks and add it to this very site. I will describe the steps below.
|
|
This book was amazing, I was thinking that the amount of pages the book offers wouldn’t be able to tell a good story but this…
|
|
Figure 1: Sample screenshot editing my .vimrc Vim is an excellent text editor. I've used it for many years and like most vim users, have collected a fairly large collection of settings in my .vimrc and learned how to grok my vim usage effectively through a lot of trial and error. To that end, I've tried to assemble a useful overview of my experience with vim. Foreword: Why? Why would you want to even put in the effort to ....
|
|
Solved: Jetty doesn't show errors on web application start-up
-
www.databasesandlife.com
-
12 years ago
-
eng
From a certain version of the “jetty” package in Debian Linux, if the web application didn’t start up (servlet init() throws an Exception), this error wasn’t logged anywhere. The solution is to install the libjetty-extra package. sudo apt-get install libjetty-extra It took some amount of experimentation to find the solution. I don’t know why you’d ever want to not log errors; i.e. why the logging of errors is an “extra”.
|
|
Recently, Phil Robertson of the sensational cable TV program Duck Dynasty has drawn quite a bit of flack for his very Christian views kept largely hidden until now through A&E’s refusal to air his more candid statements. Setting personal opinions aside though and totally disregard the absurdity of crucifying Phil for his beliefs because today’s hyper-sensitive, disgustingly entitled society seeks to vilify everyone who challenges their nu..
|
In the previous three posts we created a simple ToDo application with Ruby on Rails. In this last part we are going to deploy the application to OpenShift. You can find the complete code of the tutorial here . OpenShift OpenShift is a cloud application platform (by Red Hat). Few months ago, when I was discovering Ruby & Ruby on Rails I started developing an application in order to practice. When I completed the first version I w....
|
In the previous three posts we created a simple ToDo application with Ruby on Rails. In this last part we are going to deploy the application to OpenShift. You can find the complete code of the tutorial here . OpenShift OpenShift is a cloud application platform (by Red Hat). Few months ago, when I was discovering Ruby & Ruby on Rails I started developing an application in order to practice. When I completed the first version I w....
|
|
When I joined college I was a pretty bad swimmer. During freshman year I took some beginner/intermediate swimming classes and learned proper swimming technique for stomach crawl, breaststroke and butterfly. The next year I saw this class called Master’s swimming, spoke to the coach and signed up for it. I was by far the weakest swimmer in the class. Everybody else had great stamina and technique. We would do series of 50 metres swimming f....
|
|
Well, One Game a Month is done! I’ve managed to complete 12 games for the year. My motivation by the end was lacking, so I took it kind of easy this month and made a very simple and quick game called Simon Says . Last month’s game, 9 to 5 , took much longer due to the number of art assets required. I’ll write a proper post about the challenge, how everything went, etc later.
|
|
As I previously wrote, I’ve been busy with Vagrant on Fedora with libvirt , and have even been submitting , patches and issues ! ( This “ closed ” issue needs solving! ) Here are some of the tricks that I’ve used while hacking away. Default provider : I should have mentioned this in my earlier article but I forgot: If you’re always using the same provider, you might want to set it as the default. In my case I’m using vagrant-lib..
|