|
Deviant Ollam, Introduction to Lockpicking and Physical Security
-
www.defcon.org
-
13 years ago
-
eng
Physical security isn't just a concern of the IT world. Besides securing server rooms, locks of all sizes and styles are scattered throughout our lives. However, much of the general public is unaware of the insecurities present in many lock designs. Through discussion and direct example, Deviant Ollam will address the strengths and weaknesses of standard pin tumbler locks, combination locks, warded locks, wafer locks, and more. Discussion o....
|
|
Deviant Ollam, Introduction to Lockpicking and Physical Security
-
www.defcon.org
-
13 years ago
-
eng
Physical security isn't just a concern of the IT world. Besides securing server rooms, locks of all sizes and styles are scattered throughout our lives. However, much of the general public is unaware of the insecurities present in many lock designs. Through discussion and direct example, Deviant Ollam will address the strengths and weaknesses of standard pin tumbler locks, combination locks, warded locks, wafer locks, and more. Discussion o....
|
|
Kristofer Erickson, The Power to Map: How Cyberspace Is Imagined Through Cartography
-
www.defcon.org
-
13 years ago
-
eng
An ongoing project for scholars in Geography has been to explore how power and cartography are mutually implicated. Geographers have traditionally been concerned with making maps of the earth, but until recently we have seldom reflected on how particular forms of knowledge and power are privileged in the production of maps, and how those maps themselves produce particular geographic imaginations. As new virtual spaces are opened up through ....
|
|
Have you ever been pulled over by the Cops? Do you worry about your home being searched by the Feds? The Hacker's Guide to Search and Arrest is presented in a down and dirty fast pace. You won't hear a single boring case citation here. Instead you get information you can use in every day life, presented in a way that won't make your eyes gaze over. Learn when the Government can legally perform searches or make arrests. Find out what you ca..
|
|
Kristofer Erickson, The Power to Map: How Cyberspace Is Imagined Through Cartography
-
www.defcon.org
-
13 years ago
-
eng
An ongoing project for scholars in Geography has been to explore how power and cartography are mutually implicated. Geographers have traditionally been concerned with making maps of the earth, but until recently we have seldom reflected on how particular forms of knowledge and power are privileged in the production of maps, and how those maps themselves produce particular geographic imaginations. As new virtual spaces are opened up through ....
|
|
Have you ever been pulled over by the Cops? Do you worry about your home being searched by the Feds? The Hacker's Guide to Search and Arrest is presented in a down and dirty fast pace. You won't hear a single boring case citation here. Instead you get information you can use in every day life, presented in a way that won't make your eyes gaze over. Learn when the Government can legally perform searches or make arrests. Find out what you ca..
|
|
Leonard Gallion, A Safecracking Double Feature: Dial "B" For BackDialing and Spike the Wonder Safe
-
www.defcon.org
-
13 years ago
-
eng
This presentation will introduce two powerful, non-destructive safe opening techniques. The first "Dial B For BackDialing," will trace the history of back dialing all the way from Richard Feynman working on the atomic bomb (and opening safes) in the 1940's, to today. This presentation will show how mechanical safes have changed since Feynman's time, but how most are still vulnerable to both his method and the simpler Nascar(tm) technique. T....
|
|
Leonard Gallion, A Safecracking Double Feature: Dial "B" For BackDialing and Spike the Wonder Safe
-
www.defcon.org
-
13 years ago
-
eng
This presentation will introduce two powerful, non-destructive safe opening techniques. The first "Dial B For BackDialing," will trace the history of back dialing all the way from Richard Feynman working on the atomic bomb (and opening safes) in the 1940's, to today. This presentation will show how mechanical safes have changed since Feynman's time, but how most are still vulnerable to both his method and the simpler Nascar(tm) technique. T....
|
|
Kenneth Geers, Hacking in a Foreign Language: A Network Security Guide to Russia (and Beyond)
-
www.defcon.org
-
13 years ago
-
eng
Has your network ever been hacked, and all you have to show for your investigative efforts is an IP address belonging to an ISP in Irkutsk? Are you tired of receiving e-mails from Citibank that resolve to Muscovite IP addresses? Would you like to hack the Kremlin? Or do you think that the Kremlin has probably owned you first? Maybe you just think that Anna Kournikova is hot. If the answer to any of the above questions is yes, then you need ....
|
|
Kenneth Geers, Hacking in a Foreign Language: A Network Security Guide to Russia (and Beyond)
-
www.defcon.org
-
13 years ago
-
eng
Has your network ever been hacked, and all you have to show for your investigative efforts is an IP address belonging to an ISP in Irkutsk? Are you tired of receiving e-mails from Citibank that resolve to Muscovite IP addresses? Would you like to hack the Kremlin? Or do you think that the Kremlin has probably owned you first? Maybe you just think that Anna Kournikova is hot. If the answer to any of the above questions is yes, then you need ....
|
|
This will be a practical and theoretical tutorial on legal issues related to computer security practices. In advance of the talk, Granick will unscientifically determine the "Top Ten Legal Questions About Computer Security" that Defcon attendees have and will answer them as clearly as the unsettled nature of the law allows. While the content of the talk is audience driven, Granick expects to cover legal issues related to vulnerability discl....
|
|
Previous attempts to hack the connection between wealth and power have aimed mainly at eliminating economic inequality. They've all ended in disaster, because economic inequality is closely related to risk: you can't eliminate inequality without eliminating startups, and with them growth. So if you want to get rid of injustice, the place to attack is one step downstream, where wealth turns into power. Paul Graham is the author of On Li..
|
|
This will be a practical and theoretical tutorial on legal issues related to computer security practices. In advance of the talk, Granick will unscientifically determine the "Top Ten Legal Questions About Computer Security" that Defcon attendees have and will answer them as clearly as the unsettled nature of the law allows. While the content of the talk is audience driven, Granick expects to cover legal issues related to vulnerability discl....
|
|
Previous attempts to hack the connection between wealth and power have aimed mainly at eliminating economic inequality. They've all ended in disaster, because economic inequality is closely related to risk: you can't eliminate inequality without eliminating startups, and with them growth. So if you want to get rid of injustice, the place to attack is one step downstream, where wealth turns into power. Paul Graham is the author of On Li..
|
|
Julian Grizzard, Surgical Recovery from Kernel-Level Rootkit Installations
-
www.defcon.org
-
13 years ago
-
eng
Conventional wisdom states that once a system has been compromised, it can no longer be trusted and the only solution is to wipe the system clean and reinstall. This talk goes against the grain of conventional wisdom and asks are there more efficient ways to repair a system other than complete reinstallation. Specifically, this talk will focus on the detection of and recovery from the installation of both traditional and kernel-level rootki....
|
|
Julian Grizzard, Surgical Recovery from Kernel-Level Rootkit Installations
-
www.defcon.org
-
13 years ago
-
eng
Conventional wisdom states that once a system has been compromised, it can no longer be trusted and the only solution is to wipe the system clean and reinstall. This talk goes against the grain of conventional wisdom and asks are there more efficient ways to repair a system other than complete reinstallation. Specifically, this talk will focus on the detection of and recovery from the installation of both traditional and kernel-level rootki....
|
|
The insecure workstation II "Bob Reloaded". Exploring attack vectors within Microsoft desktop systems. A close look at third party applications that still suffer from api call vulnerabilities and how attackers can use these vulnerabilities to escalate there rights to system level . Also will be exploring this year's security research into "attacks against the local desktop login". Demonstration of desktop access without logging in. Der..
|
|
The insecure workstation II "Bob Reloaded". Exploring attack vectors within Microsoft desktop systems. A close look at third party applications that still suffer from api call vulnerabilities and how attackers can use these vulnerabilities to escalate there rights to system level . Also will be exploring this year's security research into "attacks against the local desktop login". Demonstration of desktop access without logging in. Der..
|
|
Thomas J. Holt, No Women Allowed? Exploring Gender Differences In Hacking
-
www.defcon.org
-
13 years ago
-
eng
The President of Harvard University, Lawrence H. Summers, recently suggested the lack of women in the sciences is due to innate differences between men and women. He speculated a variety of reasons for this including genetics and social factors, and his comments created a stir among academics and the general public. While the accuracy of his statements are suspect, he raises an intriguing question in light of declining female enrollment in ....
|
|
Thomas J. Holt, No Women Allowed? Exploring Gender Differences In Hacking
-
www.defcon.org
-
13 years ago
-
eng
The President of Harvard University, Lawrence H. Summers, recently suggested the lack of women in the sciences is due to innate differences between men and women. He speculated a variety of reasons for this including genetics and social factors, and his comments created a stir among academics and the general public. While the accuracy of his statements are suspect, he raises an intriguing question in light of declining female enrollment in ....
|
|
Google Hacking returns for more guaranteed fun this year at Defcon 13! If you haven't caught one of Johnny's Google talks, you definitely should. Come and witness all the new and amazing things that can be done with Google. All new for Defcon 13, Johnny reveals basic and advanced search techniques, basic and advanced hacking techniques, multi-engine attack query morphing, and zero-packet target foot printing and recon techniques. Check out ....
|
|
Google Hacking returns for more guaranteed fun this year at Defcon 13! If you haven't caught one of Johnny's Google talks, you definitely should. Come and witness all the new and amazing things that can be done with Google. All new for Defcon 13, Johnny reveals basic and advanced search techniques, basic and advanced hacking techniques, multi-engine attack query morphing, and zero-packet target foot printing and recon techniques. Check out ....
|
|
In this day and age, forensics evidence lurks everywhere. This talk takes attendees on a brisk walk through the modern technological landscape in search of hidden digital data. Some hiding places are more obvious than others, but far too many devices are overlooked in a modern forensics investigation. As we touch on each device, we'll talk about the possibilities for the forensic investigator, and take a surprising and fun look at the nooks....
|
|
In this day and age, forensics evidence lurks everywhere. This talk takes attendees on a brisk walk through the modern technological landscape in search of hidden digital data. Some hiding places are more obvious than others, but far too many devices are overlooked in a modern forensics investigation. As we touch on each device, we'll talk about the possibilities for the forensic investigator, and take a surprising and fun look at the nooks....
|
|
The Winsock SPI, or Service Provider Interface, has been a part of Winsock since the advent of version 2.0. It enables providers to extend the Winsock API transparently, by installing their own hooks and chains to application API calls. However, its formidable capabilities are not put to widespread use... aside from spyware (remember Kazaa's "sporder.dll"?). The talk will discuss (and demonstrate) some of the more insidious uses of the....
|
|
The Winsock SPI, or Service Provider Interface, has been a part of Winsock since the advent of version 2.0. It enables providers to extend the Winsock API transparently, by installing their own hooks and chains to application API calls. However, its formidable capabilities are not put to widespread use... aside from spyware (remember Kazaa's "sporder.dll"?). The talk will discuss (and demonstrate) some of the more insidious uses of the....
|
|
Sick of hand-coding each and every exploit? The past few years have seen the rise of some generalized frameworks for the exploitation of vulnerabilities, but none of them are general-purpose enough to accommodate arbitrary hardware and network protocols. By applying programming language theory to the development of new networks attacks, we can create next-generation platforms capable of quickly handling arbitrary protocols and hardware, and....
|
|
Sick of hand-coding each and every exploit? The past few years have seen the rise of some generalized frameworks for the exploitation of vulnerabilities, but none of them are general-purpose enough to accommodate arbitrary hardware and network protocols. By applying programming language theory to the development of new networks attacks, we can create next-generation platforms capable of quickly handling arbitrary protocols and hardware, and....
|
|
Traditionally, IDS systems such as snort have been used to monitor attacks against or within a network. This talk will give the outline for turning those tools around and instead using them to audit networks. We will discuss how to identify OS, tell who is patching, what services are being deployed (perhaps insecurely), and other methods for policy enforcement. This discussion is ideally suited for administrators and security professionals ....
|
|
Traditionally, IDS systems such as snort have been used to monitor attacks against or within a network. This talk will give the outline for turning those tools around and instead using them to audit networks. We will discuss how to identify OS, tell who is patching, what services are being deployed (perhaps insecurely), and other methods for policy enforcement. This discussion is ideally suited for administrators and security professionals ....
|
|
Robert "hackajar" Imhoff-Dousharm,Credit Cards: Everything You have Ever Wanted to Know
-
www.defcon.org
-
13 years ago
-
eng
Identity theft is at an all time high. With businesses, universities and banks being compromised the threat is real right now. The media covers these area's but miss one important location that your most suseptiable to fraud, everywhere you swipe your credit card. We will pull out all the stops to help you understand credit cards, their history and how to protect yourself. Ever wonder what was in the magnetic strip of a card? Where that inf....
|
|
Robert "hackajar" Imhoff-Dousharm,Credit Cards: Everything You have Ever Wanted to Know
-
www.defcon.org
-
13 years ago
-
eng
Identity theft is at an all time high. With businesses, universities and banks being compromised the threat is real right now. The media covers these area's but miss one important location that your most suseptiable to fraud, everywhere you swipe your credit card. We will pull out all the stops to help you understand credit cards, their history and how to protect yourself. Ever wonder what was in the magnetic strip of a card? Where that inf....
|
|
Encryption is simply the act of obfuscating something to the point that it would take too much time or money for an attacker to recover it. Many algorithms have time after time failed due to Moore's law or large budgets or resources (e.g. distributed.net). There have been many articles published on cracking crypto using specialized hardware, but many were never fully regarded as being practical attacks. Slowly FPGAs (Field Programmable Gate....
|
|
Encryption is simply the act of obfuscating something to the point that it would take too much time or money for an attacker to recover it. Many algorithms have time after time failed due to Moore's law or large budgets or resources (e.g. distributed.net). There have been many articles published on cracking crypto using specialized hardware, but many were never fully regarded as being practical attacks. Slowly FPGAs (Field Programmable Gate....
|
|
Tony Howlett, GeoIP Blocking, A Controversial But (Sometimes) Effective Approach
-
www.defcon.org
-
13 years ago
-
eng
What if I told you, than in a few minutes and at no extra cost, you could be blocking up to 30% of all malware headed for your network? Sound to good to be true? Well it doesn't work for everyone and there are a lot of caveats, but it can be an effective way to eliminate a large portion of the malicious traffic aimed at your network. In this talk we will cover why you would want to GeoIP block and why it might not be a good choice for you....
|
|
Tony Howlett, GeoIP Blocking, A Controversial But (Sometimes) Effective Approach
-
www.defcon.org
-
13 years ago
-
eng
What if I told you, than in a few minutes and at no extra cost, you could be blocking up to 30% of all malware headed for your network? Sound to good to be true? Well it doesn't work for everyone and there are a lot of caveats, but it can be an effective way to eliminate a large portion of the malicious traffic aimed at your network. In this talk we will cover why you would want to GeoIP block and why it might not be a good choice for you....
|
|
Technology trends are treacherous. Should you learn java or visual basic? Pay for Windows or download Linux? Will that investment in Bluetooth pay off? Or will you get suckered by a faddish book written by a fading technology guru? You can't know the future (yet), but you can make educated guesses and tilt the odds in your favor. Meme Miner is a simple program for trend tracking. Its power lies in the business and social bandwidth conc....
|
|
Technology trends are treacherous. Should you learn java or visual basic? Pay for Windows or download Linux? Will that investment in Bluetooth pay off? Or will you get suckered by a faddish book written by a fading technology guru? You can't know the future (yet), but you can make educated guesses and tilt the odds in your favor. Meme Miner is a simple program for trend tracking. Its power lies in the business and social bandwidth conc....
|
|
Kevin McCarthy, The Six Year Old Hacker: No More Script Kiddies
-
www.defcon.org
-
13 years ago
-
eng
Computer use in elementary schools is problematic. Seldom are computers well integrated into the general curriculum. Often, they are used merely as instructional surrogates to "drill" skills. Particularly disturbing is the lack of exploration of the computer itself, and the culture of technology. Programming can teach vital problem solving skills, project management, respect for others work, and the value of collaboration. So why not cultiv....
|
|
Kevin McCarthy, The Six Year Old Hacker: No More Script Kiddies
-
www.defcon.org
-
13 years ago
-
eng
Computer use in elementary schools is problematic. Seldom are computers well integrated into the general curriculum. Often, they are used merely as instructional surrogates to "drill" skills. Particularly disturbing is the lack of exploration of the computer itself, and the culture of technology. Programming can teach vital problem solving skills, project management, respect for others work, and the value of collaboration. So why not cultiv....
|
|
Trust Transience: Post Intrusion SSH Hijacking explores the issues of transient trust relationships between hosts, and how to exploit them. Applying technique from anti-forensics, linux VXers, and some good-ole-fashioned blackhat creativity, a concrete example is presented in the form of a post-intrusion transparent SSH connection hijacker. The presentation covers the theory, a real world demonstration, the implementation of the SSH Hijacke....
|
|
A unique opportunity to surrender and confess all of your crimes to law enforcement agents from multiple federal and possibly international agencies. The "Meet the Fed" Panel is again chaired by Special Agent Jim Christy, Director of the Department of Defense Cyber Crime Institute. Jim will have on his panel representatives from: * Department of Defense Cyber Crime Center (DoD) * The Internal Revenue Service (IRS - always a favorite)..
|
|
Trust Transience: Post Intrusion SSH Hijacking explores the issues of transient trust relationships between hosts, and how to exploit them. Applying technique from anti-forensics, linux VXers, and some good-ole-fashioned blackhat creativity, a concrete example is presented in the form of a post-intrusion transparent SSH connection hijacker. The presentation covers the theory, a real world demonstration, the implementation of the SSH Hijacke....
|
|
A unique opportunity to surrender and confess all of your crimes to law enforcement agents from multiple federal and possibly international agencies. The "Meet the Fed" Panel is again chaired by Special Agent Jim Christy, Director of the Department of Defense Cyber Crime Institute. Jim will have on his panel representatives from: * Department of Defense Cyber Crime Center (DoD) * The Internal Revenue Service (IRS - always a favorite)..
|