DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
Meet the VCs PING LI PARTNER, ACCEL PARTNERS MATT OCKO PARTNER, DATA COLLECTIVE DEEPAK JEEVANKUMAR PARTNER, GENERAL CATALYST JOHN M. JACK BOARD PARTNER, ANDREESSEN HOROWITZ EILEEN BURBIDGE PARTNER, PASSION CAPITAL Venture capital investments have reached the highest level since the dot-com days. Almost seven billion dollars was invested last quarter alone. While clean-tech deals hit a new low, security deals increased the most. ....
|
Meet the VCs PING LI PARTNER, ACCEL PARTNERS MATT OCKO PARTNER, DATA COLLECTIVE DEEPAK JEEVANKUMAR PARTNER, GENERAL CATALYST JOHN M. JACK BOARD PARTNER, ANDREESSEN HOROWITZ EILEEN BURBIDGE PARTNER, PASSION CAPITAL Venture capital investments have reached the highest level since the dot-com days. Almost seven billion dollars was invested last quarter alone. While clean-tech deals hit a new low, security deals increased the most. ....
|
Ask the EFF: The Year in Digital Civil Liberties KURT OPSAHL ELECTRONIC FRONTIER FOUNDATION MARCIA HOFFMANN FELLOW, EFF DAN AUERBACH STAFF TECHNOLOGIST, EFF EVA GALPERIN GLOBAL POLICY ANALYST, EFF MARC JAYCOX POLICY ANALYST AND LEGISLATIVE ASSISTANT, EFF MITCH STOLTZ STAFF ATTORNEY, EFF Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundati....
|
Ask the EFF: The Year in Digital Civil Liberties KURT OPSAHL ELECTRONIC FRONTIER FOUNDATION MARCIA HOFFMANN FELLOW, EFF DAN AUERBACH STAFF TECHNOLOGIST, EFF EVA GALPERIN GLOBAL POLICY ANALYST, EFF MARC JAYCOX POLICY ANALYST AND LEGISLATIVE ASSISTANT, EFF MITCH STOLTZ STAFF ATTORNEY, EFF Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundati....
|
The ACLU Presents: NSA Surveillance and More ALEX ABDO STAFF ATTORNEY, ACLU NATIONAL SECURITY PROJECT CATHERINE CRUMP STAFF ATTORNEY, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT KADE CROCKFORD ACLU OF MASSACHUSETTS TECHNOLOGY FOR LIBERTY PROJECT NICOLE OZER TECHNOLOGY AND CIVIL LIBERTIES POLICY DIRECTOR, ACLU OF CALIFORNIA From the NSA's PRISM and....
|
The ACLU Presents: NSA Surveillance and More ALEX ABDO STAFF ATTORNEY, ACLU NATIONAL SECURITY PROJECT CATHERINE CRUMP STAFF ATTORNEY, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT KADE CROCKFORD ACLU OF MASSACHUSETTS TECHNOLOGY FOR LIBERTY PROJECT NICOLE OZER TECHNOLOGY AND CIVIL LIBERTIES POLICY DIRECTOR, ACLU OF CALIFORNIA From the NSA's PRISM and....
|
Hacking Driverless Vehicles ZOZ CANNYTROPHIC DESIGN Are driverless vehicles ripe for the hacking? Autonomous and unmanned systems are already patrolling our skies and oceans and being tested on our streets and highways. All trends indicate these systems are at an inflection point that will show them rapidly becoming commonplace. It is therefore a salient time for a discussion of the capabilities and potential vulnerabilities of these sy....
|
Android WebLogin: Google's Skeleton Key CRAIG YOUNG VERT SECURITY RESEARCHER, TRIPWIRE Millions of businesses worldwide trust in Google Apps to run their organization's domain. The life-blood of these organizations is routinely stored with Google accounts and accessed with mobile devices. This talk explores how an adversary can parlay the compromise of a single Android device into a complete Google apps domain takeover. The attack vecto....
|
Android WebLogin: Google's Skeleton Key CRAIG YOUNG VERT SECURITY RESEARCHER, TRIPWIRE Millions of businesses worldwide trust in Google Apps to run their organization's domain. The life-blood of these organizations is routinely stored with Google accounts and accessed with mobile devices. This talk explores how an adversary can parlay the compromise of a single Android device into a complete Google apps domain takeover. The attack vecto....
|
BYOD PEAP Show JOSH YAVOR ISEC PARTNERS The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no long....
|
BYOD PEAP Show JOSH YAVOR ISEC PARTNERS The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no long....
|
Reality Hackers REBECCA WEXLER DIRECTOR/PRODUCER YALE VISUAL LAW PROJECT PAUL SANDERSON DIRECTOR/PRODUCER OUR TOWN FILMS Reality Hackers. Technology, wit, and hacker culture fuse in an electrified movement for digital freedom. Meet the activists who make and break technology to ensure free speech and private communication for political dissidents, and to combat global censorship. This film gives a behind-the-scenes look at those who a....
|
|
Mark Weatherford - The Growing Irrelevance of US Government Cybersecurity Intelligence Information
-
media.defcon.org
-
12 years ago
-
eng
The Growing Irrelevance of US Government Cybersecurity Intelligence Information MARK WEATHERFORD PRINCIPAL, THE CHERTOFF GROUP The rapidly changing threat landscape has finally provided relevant business justification for commercial companies to invest in developing cybersecurity intelligence that used to be the domain of the government – and they are doing it at a pace that is making the value of government “Classified" cybersecurity i....
|
|
Mark Weatherford - The Growing Irrelevance of US Government Cybersecurity Intelligence Information
-
media.defcon.org
-
12 years ago
-
eng
The Growing Irrelevance of US Government Cybersecurity Intelligence Information MARK WEATHERFORD PRINCIPAL, THE CHERTOFF GROUP The rapidly changing threat landscape has finally provided relevant business justification for commercial companies to invest in developing cybersecurity intelligence that used to be the domain of the government – and they are doing it at a pace that is making the value of government “Classified" cybersecurity i....
|
HTTP Time Bandit VAAGN TOUKHARIAN PRINCIPAL ENGINEER, QUALYS TIGRAN GEVORGYAN ENGINEERING MANAGER, QUALYS While web applications have become richer to provide a higher level user experience, they run increasingly large amounts of code on both the server and client sides. A few of the pages on the web server may be performance bottlenecks. Identifying those pages gives both application owners as well as potential attackers the chance t....
|
|
Marc Weber Tobias and Tobias Bluzmanis - Insecurity - A Failure of Imagination
-
www.defcon.org
-
12 years ago
-
eng
Insecurity - A Failure of Imagination MARC WEBER TOBIAS INVESTIGATIVE ATTORNEY AND SECURITY SPECIALIST, SECURITY.ORG TOBIAS BLUZMANIS SECURITY SPECIALIST, SECURITY.ORG Homeowners, apartment complexes, and businesses throughout the United States and Canada have purchased locks from one of the leading manufacturers in the country in the belief that they were secure. Advertising represents they are the highest grade of residential securi....
|
|
Marc Weber Tobias and Tobias Bluzmanis - Insecurity - A Failure of Imagination
-
media.defcon.org
-
12 years ago
-
eng
Insecurity - A Failure of Imagination MARC WEBER TOBIAS INVESTIGATIVE ATTORNEY AND SECURITY SPECIALIST, SECURITY.ORG TOBIAS BLUZMANIS SECURITY SPECIALIST, SECURITY.ORG Homeowners, apartment complexes, and businesses throughout the United States and Canada have purchased locks from one of the leading manufacturers in the country in the belief that they were secure. Advertising represents they are the highest grade of residential securi....
|
|
Jacob Thompson - C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood
-
www.defcon.org
-
12 years ago
-
eng
C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood JACOB THOMPSON Common wisdom dictates that web applications serving sensitive data must use an encrypted connection (i.e., HTTPS) to protect data in transit. Once served, that same sensitive data must be protected at rest, either through encryption, or more appropriately by not storing the sensitive data on disk at all. In the past, web browser disk caching policies maintained a ....
|
|
Jacob Thompson - C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood
-
media.defcon.org
-
12 years ago
-
eng
C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood JACOB THOMPSON Common wisdom dictates that web applications serving sensitive data must use an encrypted connection (i.e., HTTPS) to protect data in transit. Once served, that same sensitive data must be protected at rest, either through encryption, or more appropriately by not storing the sensitive data on disk at all. In the past, web browser disk caching policies maintained a ....
|
|
Josh 'm0nk' Thomas - BoutiqueKit: Playing WarGames with expensive rootkits and malware
-
www.defcon.org
-
12 years ago
-
eng
BoutiqueKit: Playing WarGames with expensive rootkits and malware JOSH 'M0NK' THOMAS APPLIED RESEARCH SCIENTIST - ACCUVANT "Theoretical" targeted rootkits need to play by different rules than the common malware that ends up filling our inboxes with spam and attempting to steal our CC numbers... The costs involved of getting popped are huge in comparison, the value is in the secrecy of being truly hidden and embedded for the long term. ....
|
|
Josh 'm0nk' Thomas - BoutiqueKit: Playing WarGames with expensive rootkits and malware
-
media.defcon.org
-
12 years ago
-
eng
BoutiqueKit: Playing WarGames with expensive rootkits and malware JOSH 'M0NK' THOMAS APPLIED RESEARCH SCIENTIST - ACCUVANT "Theoretical" targeted rootkits need to play by different rules than the common malware that ends up filling our inboxes with spam and attempting to steal our CC numbers... The costs involved of getting popped are huge in comparison, the value is in the secrecy of being truly hidden and embedded for the long term. ....
|
|
Richard Thieme - The Government and UFOs: A Historical Analysis by Richard Thieme
-
www.defcon.org
-
12 years ago
-
eng
The Government and UFOs: A Historical Analysis by Richard Thieme RICHARD THIEME This talk is about the ways the many components of governments interact and respond to challenging and anomalous events--highly relevant to hacking by all definitions and at all levels. If you donít know the lay of the land, you can not engage in appropriate research and reconnaissance, counter-measures, and operations. The proliferation of reliable repor....
|
|
Richard Thieme - The Government and UFOs: A Historical Analysis by Richard Thieme
-
media.defcon.org
-
12 years ago
-
eng
The Government and UFOs: A Historical Analysis by Richard Thieme RICHARD THIEME This talk is about the ways the many components of governments interact and respond to challenging and anomalous events--highly relevant to hacking by all definitions and at all levels. If you donít know the lay of the land, you can not engage in appropriate research and reconnaissance, counter-measures, and operations. The proliferation of reliable repor....
|
EDS: Exploitation Detection System AMR THABET MALWARE RESEARCHER, Q-CERT In the last several years, exploits have become the strongest weapons in cyber warfare. Exploit developers and vulnerability researchers have now become the nuclear scientists of the digital world. OS Companies and third party companies have created several security mitigation tools to make it harder to use these vulnerabilities and have made exploit creation harde....
|
EDS: Exploitation Detection System AMR THABET MALWARE RESEARCHER, Q-CERT In the last several years, exploits have become the strongest weapons in cyber warfare. Exploit developers and vulnerability researchers have now become the nuclear scientists of the digital world. OS Companies and third party companies have created several security mitigation tools to make it harder to use these vulnerabilities and have made exploit creation harde....
|
|
Chris Sumner and Randall Wald - Predicting Susceptibility to Social Bots on Twitter
-
www.defcon.org
-
12 years ago
-
eng
Predicting Susceptibility to Social Bots on Twitter CHRIS SUMNER RANDALL WALD Are some Twitter users more naturally predisposed to interacting with social bots and can social bot creators exploit this knowledge to increase the odds of getting a response? Social bots are growing more intelligent, moving beyond simple reposts of boilerplate ad content to attempt to engage with users and then exploit this trust to promote a product or....
|
|
Chris Sumner and Randall Wald - Predicting Susceptibility to Social Bots on Twitter
-
media.defcon.org
-
12 years ago
-
eng
Predicting Susceptibility to Social Bots on Twitter CHRIS SUMNER RANDALL WALD Are some Twitter users more naturally predisposed to interacting with social bots and can social bot creators exploit this knowledge to increase the odds of getting a response? Social bots are growing more intelligent, moving beyond simple reposts of boilerplate ad content to attempt to engage with users and then exploit this trust to promote a product or....
|
DNS May Be Hazardous to Your Health ROBERT STUCKE SECURITY RESEARCHER The largest manufacturer of laptops, one of the largest consulting firms, and a big data behemoth all walk into a bar... His research explores many self-inflicted gaps that continue to plague even the largest companies. These gaps are often seen as trivial and ignored, thus making all of their DNS investments lead to a false sense of security. Too much effort and t....
|
DNS May Be Hazardous to Your Health ROBERT STUCKE SECURITY RESEARCHER The largest manufacturer of laptops, one of the largest consulting firms, and a big data behemoth all walk into a bar... His research explores many self-inflicted gaps that continue to plague even the largest companies. These gaps are often seen as trivial and ignored, thus making all of their DNS investments lead to a false sense of security. Too much effort and t....
|
|
Tom Steele and Dan Kottmann - Collaborative Penetration Testing With Lair
-
www.defcon.org
-
12 years ago
-
eng
Collaborative Penetration Testing With Lair TOM STEELE SENIOR SECURITY CONSULTANT, FISHNET SECURITY DAN KOTTMANN SECURITY CONSULTANT, FISHNET SECURITY Lair is an open-source project developed for and by pentesters. Built on Meteor and Node.js with a dash of Python, Lair is a web application that normalizes, centralizes, and manages diverse test data from a number of common tools including Nmap, Nessus, Nexpose, and Burp. Unlike existi....
|
|
Jason Staggs - How to Hack Your Mini Cooper: Reverse Engineering Controller Area Network (CAN) Messages on Passenger Automobiles
-
www.defcon.org
-
12 years ago
-
eng
How to Hack Your Mini Cooper: Reverse Engineering Controller Area Network (CAN) Messages on Passenger Automobiles JASON STAGGS GRAD STUDENT AND RESEARCH ASSISTANT, UNIVERSITY OF TULSA This presentation introduces the underlying protocols on automobile communication system networks of passenger vehicles and evaluates their security. Although reliable for communication, vehicle protocols lack inherit security measures. This work focuses s....
|
|
Jason Staggs - How to Hack Your Mini Cooper: Reverse Engineering Controller Area Network (CAN) Messages on Passenger Automobiles
-
media.defcon.org
-
12 years ago
-
eng
How to Hack Your Mini Cooper: Reverse Engineering Controller Area Network (CAN) Messages on Passenger Automobiles JASON STAGGS GRAD STUDENT AND RESEARCH ASSISTANT, UNIVERSITY OF TULSA This presentation introduces the underlying protocols on automobile communication system networks of passenger vehicles and evaluates their security. Although reliable for communication, vehicle protocols lack inherit security measures. This work focuses s....
|
Evolving Exploits Through Genetic Algorithms SOEN HACKER FOR TEAM VANNED This talk will discuss the next logical step from dumb fuzzing to breeding exploits via machine learning & evolution. Using genetic algorithms, this talk will take simple SQL exploits and breed them into precision tactical weapons. Stop looking at SQL error messages and carefully crafting injections, let genetic algorithms take over and create lethal exploits to PW..
|
|
Djwishbone and PuNk1nPo0p - BYO-Disaster and Why Corporate Wireless Security Still Sucks
-
www.defcon.org
-
12 years ago
-
eng
BYO-Disaster and Why Corporate Wireless Security Still Sucks JAMES SNODGRASS (PUNK1NPO0P) HILLBILLY HACKER JOSH HOOVER (WISHBONE) HILLBILLY HACKER Right when you thought this topic had been beaten to death, something new emerges. This horse isn’t dead yet! This talk will focus on a completely new vulnerability in the way some devices handle MsChapV2 and present some newer methods for capturing clear text credentials easily and without....
|
|
Djwishbone and PuNk1nPo0p - BYO-Disaster and Why Corporate Wireless Security Still Sucks
-
media.defcon.org
-
12 years ago
-
eng
BYO-Disaster and Why Corporate Wireless Security Still Sucks JAMES SNODGRASS (PUNK1NPO0P) HILLBILLY HACKER JOSH HOOVER (WISHBONE) HILLBILLY HACKER Right when you thought this topic had been beaten to death, something new emerges. This horse isn’t dead yet! This talk will focus on a completely new vulnerability in the way some devices handle MsChapV2 and present some newer methods for capturing clear text credentials easily and without....
|
|
Hunter Scott - Hacking Wireless Networks of the Future: Security in Cognitive Radio Networks
-
www.defcon.org
-
12 years ago
-
eng
Hacking Wireless Networks of the Future: Security in Cognitive Radio Networks HUNTER SCOTT M2M, IoT, whatever buzzword you want to use, telecoms are predicting and preparing for a huge increase in embedded, connected devices within the next 10 years and predict spectrum utilization will increase even faster in the next 5 years. One of the ways this growth will be addressed is with cognitive radio networks. This talk will discuss the new....
|
|
Hunter Scott - Hacking Wireless Networks of the Future: Security in Cognitive Radio Networks
-
media.defcon.org
-
12 years ago
-
eng
Hacking Wireless Networks of the Future: Security in Cognitive Radio Networks HUNTER SCOTT M2M, IoT, whatever buzzword you want to use, telecoms are predicting and preparing for a huge increase in embedded, connected devices within the next 10 years and predict spectrum utilization will increase even faster in the next 5 years. One of the ways this growth will be addressed is with cognitive radio networks. This talk will discuss the new....
|