|
Mike Tassey, Rich Perkins - Wireless Aerial Surveillance Platform
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Tassey-Perkins/DEFCON-19-Tassey-Perkins-Wireless-Aerial-Surveillance-Platform.pdf Tired of theory? This session has everything you want, big yellow aircraft flown by computers, pounds of highly volatile chemicals, CUDA, 50 Amp electrical circuits and the ability to attack networks, systems and cell phones interactively from a remote location anywhere in the world. We will demo....
|
|
Richard Thieme - Staring into the Abyss: The Dark Side of Crime-fighting, Security, and Professional Intelligence
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Thieme/DEFCON-19-Thieme-Staring-into-the-Abyss-WP.pdf Nothing is harder to see than things we believe so deeply we don't even see them. This is certainly true in the "security space," in which our narratives are self-referential, bounded by mutual self-interest, and characterized by a heavy dose of group-think. That narrative serves as insulation to filter out the most critica....
|
|
Marc Weber Tobias, Matt Fiddler and Tobias Bluzmanis - Insecurity: An Analysis Of Current Commercial And Government Security Lock Designs
-
www.defcon.org
-
14 years ago
-
eng
Lock manufacturers continue to produce insecure designs in both mechanical and electro-mechanical locks. While these devices are designed to provide secure access control to commercial and government facilities, in fact many do not. Recent disclosures with regard to extremely popular push-button locks have led to an expanded investigation into their technology and security by our research team. As a consequence, it appears that mechanical l....
|
|
Ever leave the house without your picks only to find yourself in a situation where you desperately need them? Well, never fear! I'm going to explain how to open everything from cars, to briefcases to safes with objects as common as popsicle sticks and unconventional as palm sanders. Every attack will be fully explained so you understand the underlying mechanisms and how we are taking advantage of mechanical tolerances and design flaws to ow....
|
|
Marketa Trimble - The Future of Cybertravel: Legal Implications of the Evasion of Geolocation
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Trimble/DEFCON-19-Trimble-Cybertravel.ppt.pdf This presentation discusses the current legal status of evasion of geolocation and the potential liability of the user-evader or provider of an evasion tool. The presentation also projects how the law might develop to treat acts of evasion and what challenges the technical community might face in this area. The legal community....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Webb/DEFCON-19-Webb-Runtime-Process-Insemination.pdf Injecting arbitrary code during runtime in linux is a painful process. This presentation discusses current techniques and reveals a new technique not used in other projects. The proposed technique allows for anonymous injection of shared objects, the ability to pwn a process without leaving any physical evidence behind. Libh..
|
|
Matt "scriptjunkie" Weeks - Network Nightmare: Ruling The Nightlife Between Shutdown And Boot With Pxesploit
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Weeks/DEFCON-19-Weeks-Network-Nightmare.pdf The best techniques for exploitation, maintaining access, and owning in general move down the stack, using low-level code to bypass security controls. Take the preboot execution environment and get bios-level access to the hardware from across the network, outside any control of the on-disk operating system. In this presentation I wi....
|
|
Yekaterina Tsipenyuk O'Neil, Erika Chin - Seven Ways to Hang Yourself with Google Android
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/O%27Neil-Chin/DEFCON-19-O%27Neil-Chin-Google-Android.pdf According to Google, Android was designed to give mobile developers "an excellent software platform for everyday users" on which to build rich applications for the growing mobile device market. The power and flexibility of the Android platform are undeniable, but where does it leave developers when it comes to security? ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Weyers/DEFCON-19-Weyers-Key-Impressioning.pdf We've all seen lockpicking explained on several security venues. You might even have tried it yourself. But what if you need to open a lock a number of times? Wouldn't it be great to have an opening technique that would supply you with a working key in the process? A method to do this has existed for quite some time, but until rece....
|
|
Thomas Wilhelm - Staying Connected during a Revolution or Disaster
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Wilhelm/DEFCON-19-Wilhelm-Staying-Connected .pdf During the recent revolutions in Africa and the Middle East, governments have shut down both Internet and Phone services in an attempt to quell communication among demonstrators. In addition, during natural disasters, people have been left without a means of finding out the latest news regarding emergency services. We will discu....
|
|
https://www.defcon.org/html/links/dc-archives/dc-19-archive.html The only thing worse than no security is a false sense of security. And though we know, "you can't win by defense alone", our modern approaches tend to act as though offense and defense are two entirely separate things. Treating security as an issue of quality has gotten us far, however, nearly everyday, some of the largest companies are still being compromised. It's beco....
|
|
Sterling Archer, Freaksworth - IP4 TRUTH: The IPocalypse is a LIE
-
www.defcon.org
-
14 years ago
-
eng
There is a long tradition of researchers presenting at security conferences on topics that are embarrassing to a large company or government agency: ATM hacking, router vulnerabilities, Massachusetts toll road RFIDs, etc. Many of these brave researchers risk lawsuits or career ruin to reveal the truth. THIS is the first talk that puts the presenters' very lives in peril. Much has been made of the so-called "IPv4 address exhaustion" problem,....
|
|
Phil Cryer - Taking Your Ball And Going Home; Building Your Own Secure Storage Space That Mirrors Dropbox's Functionality
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Cryer/DEFCON-19-Cryer-Taking-Your-Ball-and-Going-Home.pdf When for-profit companies offer a free app, there is always going to be strings attached. As we have increasingly seen, these strings are often tied to your privacy to enable said third party company to monetize you in some way, but in worse cases your security can be compromised leaving you open to identity theft at best or l....
|
|
Jack Daniel, James Arlen, Joshua Corman, Alex Hutton, Martin McKeay & Dave Shackleford - PCI 2.0: Still Compromising Controls and Compromising Security
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/PCI-PANEL/DEFCON-19-JackDaniel-PCI-2-PANEL.pdf Building on last year's panel discussion of PCI and its impact on the world of infosec, we are back for more- including "actionable" information. Having framed the debates in the initial panel, this year we will focus on what works, what doesn't, and what we can do about it. Compliance issues in general, and PCI-DSS in particular, a....
|
|
Dark Tangent, Rod Beckstrom, Jerry Dixon, Tony Sager, Linton Wells II - Former Keynotes - The Future
-
www.defcon.org
-
14 years ago
-
eng
Former keynotes keep coming back to DEFCON. Join The Dark Tangent, Rod Beckstrom, Jerry Dixon, Tony Sager, and Linton Wells to discuss the future of cyber security. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, public diplomacy leader and, most recently, the head of a top-level federal government agency entrusted with protecting the natio....
|
Tamper evident technologies are quickly becoming an interesting topic for hackers around the world. DEF CON 18 (2010) held the first ever "Tamper Evident" contest, where contestants were given a box sealed with a variety of tamper evident devices, many of which purport to be "tamper proof." All of these devices were defeated, even by those with little experience and a limited toolkit. Like the computer world, many of these devices are overm....
|
|
Ganesh Devarajan, Don LeBert - VDLDS - All Your Voice Are Belong To Us
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Devarajan-LeBert/DEFCON-19-Devarajan-LeBert-VDLDS.pptx.pdf Anytime you want to bypass the system, you tend to have a telephone conversation instead of leaving a paper trail. Data Leakage Prevention (DLP) is on top of the list for most organizations, be it financial or medical industry. In order to overcome this issue we need to devise a new system that can monitor phone conversations....
|
|
Deviant Ollam - Safe to Armed in Seconds: A Study of Epic Fails of Popular Gun Safes
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Ollam/DEFCON-19-Ollam-Gun-Safes.pdf Hackers like guns. Hackers like locks. Hackers like to tinker with guns and locks. And, most of the time, hackers protect their guns with high-quality locks. However, while it's one thing to own a nice gun safe protected by a high security dial, that sort of solution tends to be best for the firearms that one doesn't have in daily use. Many of us w....
|
|
Whitfield Diffie and Moxie Marlinspike - Whitfield Diffie and Moxie Marlinspike
-
www.defcon.org
-
14 years ago
-
eng
Come watch Whitfield Diffie and Moxie Marlinspike talk about certificate authorities, DNSSEC, SSL, dane, trust agility and whatever else they want to. Moderated by the Dark Tangent and with Q&A from the audience.
|
|
Artem Dinaburg - Bit-squatting: DNS Hijacking Without Exploitation
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Dinaburg/DEFCON-19-Dinaburg-Bit-Squatting.pdf We are generally accustomed to assuming that computer hardware will work as described, barring deliberate sabotage. This assumption is mistaken. Poor manufacturing, errant radiation, and heat can cause malfunction. Commonly, such malfunction DRAM chips manifest as flipped bits. Security researchers have known about the danger of such bit ....
|
|
Alva 'Skip' Duckwall - A Bridge Too Far: Defeating Wired 802.1x with a Transparent Bridge Using Linux
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Duckwall/DEFCON-19-Duckwall-Bridge-Too-Far.pdf Using Linux and a device with 2 network cards, I will demonstrate how to configure an undetectable transparent bridge to inject a rogue device onto a wired network that is secured via 802.1x using an existing authorized connection. I will then demonstrate how to set up the bridge to allow remote interaction and how the entire process can....
|
|
Nelson Elhage - Virtualization under attack: Breaking out of KVM
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Elhage/DEFCON-19-Elhage-Virtualization-Under-Attack.pdf KVM, the Linux Kernel Virtual Machine, seems destined to become the dominant open-source virtualization solution on Linux. Virtually every major Linux distribution has adopted it as their standard virtualization technology for the future. And yet, to date, remarkably little work has been done on exploiting vulnerabilities to break ....
|
|
Tim Elrod, Stefan Morris - I Am Not a Doctor but I Play One on Your Network
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Elrod-Morris/DEFCON-19-Elrod-Morris-Not-a-Doctor.pdf How secure is your Protected Health Information? This talk will expose the world of Health Information Systems with an in depth technical review of their common protocols and technologies. Many of these life-critical systems had once relied on the security provided by air gapped medical networks. Recently, in an effort to realize s....
|
|
Dr. Patrick Engebretson, Dr. Josh Pauli - Mamma Don't Let Your Babies Grow Up to be Pen Testers - (a.k.a. Everything Your Guidance Counselor Forgot to Tell You About Pen Testing)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Engebretson-Pauli/DEFCON-19-Engebretson-Pauli-Pen-Testing.pdf Always wanted to be a 1337 penetration tester capable of deciphering Kryptos while simultaneously developing your own custom 0-days? Then this is NOT the talk for you. We will however make you laugh by presenting an honest look at the life and times of a penetration tester today. We promise to open your eyes to aspects of ....
|
There are a lot of great ways to hide your data from prying eyes this talk will give a crash course in the technology and some tools that can be used to secure your data. Will also discuss hiding your files in plain site so an intruder will have no idea that hidden files even exist. These same techniques can also be employed by somebody wishing to transmit messages. Eskimo (Neil Weitzel) is a Technology Analyst for Indiana University. ..
|
|
Tom Eston, Josh Abraham & Kevin Johnson - Don't Drop the SOAP: Real World Web Service Testing for Web Hacker
-
www.defcon.org
-
14 years ago
-
eng
Over the years web services have become an integral part of web and mobile applications. From critical business applications like SAP to mobile applications used by millions, web services are becoming more of an attack vector than ever before. Unfortunately, penetration testers haven't kept up with the popularity of web services, recent advancements in web service technology, testing methodologies and tools. In fact, most of the methodologi....
|
|
Ben Feinstein, Jeff Jarmoc - "Get Off of My Cloud": Cloud Credential Compromise and Exposure
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Feinstein-Jarmoc/DEFCON-19-Feinstein-Jarmoc-Get-Off-of-My-Cloud.pdf An Amazon Machine Image (AMI) is a virtual appliance container used to create virtual machines (VMs) within the Amazon Elastic Compute Cloud (EC2). EC2 instances typically interact with a variety of Amazon Web Services (AWS), and as such require access to AWS credentials and private key materials. In this presenta....
|
|
Foofus - Handicapping the US Supreme Court: Can We Get Rich by Forceful Browsing?
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Foofus/DEFCON-19-Foofus-Forceful-Browsing-WP.pdf Using only script-kiddie skills, it may be possible to handicap the outcome of decisions of national importance. This talk presents a walk-though of a project to make more accurate predictions of US Supreme Court case outcomes. That could be a useful thing, if you had something at stake. Conventional techniques for predicting outcom....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Fritschie-Witmer/DEFCON-19-Fritschie-Witmer-F-On-the-River.pdf Online poker is a multi-million dollar industry that is rapidly growing, but is not highly regulated. There have been "hacks" recently (i.e. weak SSL implementation, superuser account) that have drawn more attention to security in the poker industry, especially as it moves to full regulation in the United States. This tal....
|
|
Eric Fulton - Cellular Privacy: A Forensic Analysis of Android Network Traffic
-
www.defcon.org
-
14 years ago
-
eng
People inherently trust their phones, but should they? "Cellular Privacy: A Forensic Analysis of Android Network Traffic" is a presentation of results from forensically analyzing the network traffic of an Android phone. The results paint an interesting picture. Is Google more trustworthy than the application developers? Are legitimate market apps more trustworthy than their rooted counterparts? Perhaps most importantly, should you trust you..
|
https://www.defcon.org/defcon-19/dc-19-presentations/Garcia/DEFCON-19-Garcia-UPnP-Mapping.pdf Universal Plug and Play(UPnP) is a technology developed by Microsoft in 1999, as a solution for NAT traversal(among other things). This talk explores the exploiting of port mapping services in UPnP/IGD devices from the WAN. It also talks about a tool called Umap to help process the UPnP requests. Attacking UPnP allows attackers to use devices ....
|
|
Andrew Gavin - Gone in 60 Minutes: Stealing Sensitive Data from Thousands of Systems Simultaneously with OpenDLP
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Gavin/DEFCON-19-Gavin-OpenDLP.pdf Got domain admin to a couple of thousand Windows systems? Got an hour to spare? Steal sensitive data from all of these systems simultaneously in under an hour with OpenDLP. OpenDLP is an open source, agent-based, massively distributable, centrally managed data discovery program that runs as a service on Windows systems and is controlled from a centra....
|
|
Kenneth Geers - Strategic Cyber Security: An Evaluation of Nation-State Cyber Attack Mitigation Strategies
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security-WP.pdf This presentation argues that computer security has evolved from a technical discipline to a strategic concept. The world's growing dependence on a powerful but vulnerable Internet - combined with the disr....
|
|
Ramon Gomez - Bulletproofing The Cloud: Are We Any Closer To Security?
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Gomez/DEFCON-19-Gomez-Bulletproofing-The-Cloud.pdf Cloud security has come into focus in the last few years; while many ways to break the cloud have been proposed, few solutions have been put forward. This talk is primarily a conceptual discussion on how cloud providers can and should be (but probably are not) protecting both their own and their clients' assets in their cloud impleme....
|
|
Vlad Gostom, Joshua Marpet - Smile for the Grenade! "Camera Go Bang!"
-
www.defcon.org
-
14 years ago
-
eng
Cameras are hugely important to urban and suburban battlefields. Reconnaissance is a must-have for commanders, and a force multiplier for actual combat units. A combat-deployable camera system is being developed or used by nearly every military-industrial manufacturer and government agency, ranging from Throwable Camera Balls to Grenade-style launched cameras. But they're expensive and inaccessible to civilians. Would it be possible to buil....
|
|
Anch, blakdayz, Anarchy Angel, ngharo, Itzik Kotler, Jake "GenericSuperhero" & converge - Represent! Defcon Groups, Hackerspaces, and You.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/DC-Groups-Panel/DEFCON-19-DC-Groups-Panel.pdf Fabricating, circumventing, forging, partying, milling, crafting, building breaking - Defcon Groups have risen, fallen, and endured the last 8 years as decentralized and smoldering embers of the local hacker think-tank. This year Defcon sets out to stoke that fire and unite our groups, at and outside of the conference. The talk will co....
|
|
Nathan Hamiel, Gregory Fleischer, Justin Engler & Seth Law - Smartfuzzing The Web: Carpe Vestra Foramina
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Hamiel/DEFCON-19-Hamiel-Smartfuzzing_the_Web_DC.pdf Extra Material: https://www.defcon.org/defcon-19/dc-19-presentations/Hamiel/DEFCON-19-Hamiel-Smartfuzzing_the_Web_DC-Extras.zip It can be scary to think about how little of the modern attack surface many tools cover. There is no one best tool for the job and on top of that some tools don't do a great job at anything. Often in t....
|
|
Rob Havelt, Wendel Guglielmetti Henrique - Earth vs. The Giant Spider: Amazingly True Stories of Real Penetration Tests
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Havelt-Henrique/DEFCON-19-Havelt-Henrique.pdf Earth vs. The Giant Spider: Amazingly True Stories of Real Penetration Tests brings the DEF CON 19 audience the most massive collection of weird, downright bizarre, freaky, and altogether unlikely hacks ever seen in the wild. This talk will focus on those complex hacks found in real environments - some in very high end and important syste....
|
|
Deral Heiland - From Printer To Pwnd: Leveraging Multifunction Printers During Penetration Testing
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Heiland/DEFCON-19-Heiland-Printer-To-Pwnd.pdf https://www.defcon.org/defcon-19/dc-19-presentations/Heiland/DEFCON-19-Heiland-Printer-To-Pwnd-Extras.zip In this presentation we go beyond the common printer issues and focus on harvesting data from multifunction printer (MFP) that can be leveraged to gain access to other core network systems. By taking advantage of poor printer sec....
|
|
Thomas J. Holt, Max Kilger - Assessing Civilian Willingness to Participate in On-Line Political and Social Conflict
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Holt-Kilger/DEFCON-19-Holt-Kilger-Assessing-Civilian-Willingness.pdf Changes in the social dynamics and motivations of the hacking community are a potential catalyst that when combined with the expanding reliance of critical infrastructure components upon networked control systems may provide the genesis for the emergence of what is being called the civilian cyberwarrior The emerg....
|
|
Rick Howard - An Insider's Look at International Cyber Security Threats and Trends
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends-WP.pdf Verisign iDefense General Manager, Rick Howard, will provide an inside look into current cyber security trends with regard to Cyber War, Cyber Hacktivism, and Cyber Espionage. In this presentation Rick will ....
|
This talk will educate listeners on best practices for safety and privacy on the Internet.It aims to demonstrate the improbability of staying anonymous while engaging in group or social activities on the internet, and especially while engaging in criminal activities as a group. This talk will reveal how Hubris, A5h3r4h, and Backtrace security staged a cyber war against anonymous, using Anonymous' own methods, and how key operatives in ....
|
|
Robert "Hackajar" Imhoff-Dousharm - Economics of Password Cracking in the GPU Era
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Imhoff/DEFCON-19-Imhoff-Password-Cracking.pdf As this shift to "General Computing" and working in the cloud has accelerated in the last 4 years, so has the ability to take advantage of these technologies from an Information Security vantage point. This could not be more apparent than with the sudden uptick in GPU based password cracking technologies. In this presentation we will expl....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Jakhar/DEFCON-19-Jakhar-Jugaad-Linux-Thread-Injection.pdf Windows malware conveniently use the CreateRemoteThread() api to delegate critical tasks inside of other processes. However till now there is no API on Linux to perform such operation. This paper talks about my work on creating an API similar to createRemoteThread() on *nix OSes. The kit currently works on Linux, allocates spa....
|