|
Jason Scott - Archive Team: A Distributed Preservation of Service Attack
-
www.defcon.org
-
14 years ago
-
eng
For the last few years, historian and archivist Jason Scott has been involved with a loose, rogue band of data preservation activists called The Archive Team. As major sites with brand recognition and the work of millions announce short-notice shutdowns of their entire services, including Geocities, Friendster, and Yahoo Video, Archive Team arrives on the scene to duplicate as much as they possibly can for history before all the data is wip....
|
|
The Smart Grid brings greater benefits for utilities and customer alike, however these benefits come at a cost from a security perspective. Unlike the over-hyped messages we usually hear from the media, the sky is NOT falling. However, just like any other technology, the systems and devices that make up the Smart Grid will have weaknesses and vulnerabilities. It is important for us to understand these vulnerabilities, how they can be attack....
|
|
Jimmy Shah - Mobile App Moolah: Profit taking with Mobile Malware
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Shah/DEFCON-19-Shah-Mobile-Moolah.pdf Smartphones are a hot new market for software developers. Millions of potential customers, and a large percentage willing to part with a small sum of money for your latest creation. Even a moderately successful app can help fill your pockets. It's hard to ignore for legitimate developers. It's even harder to ignore for criminals. Thin....
|
|
When a CISO pays good money for a thorough pentesting, she wants results. Not necessarily the ones that the pentester had in mind, either. Whether the time allotted is too short, the pentester has to achieve multiple objectives, or they disagree on the severity of the findings, both the CISO and the pentester have to agree on both sides of the engagement. We discuss numerous aspects of voluntary pwnage: the differences between a security as..
|
|
Skunkworks - Hacking the Global Economy with GPUs or How I Learned to Stop Worrying and Love Bitcoin
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Skunkworks/DEFCON-19-Skunkworks-Bitcoin.pdf In the post 9/11 era when it's nearly impossible to buy a pack of gum without alerting the big three credit bureaus, you may think that anonymity is long gone from the economy. That's where bitcoin comes in. Bitcoin is a decentralized peer-to-peer currency based solely on computing power. It is (mostly) untraceable and highly anonymo..
|
|
Halloween makers or how haunters void warranties, social engineer and find the joy of creativity. A short path down to what a community of makers that mod hardware, special effect and mood you in order to scare the shit out of you just one night a year. These people comprise electrical engineers to housewives and personally I've learned to solder better, faster because of it. Reeves Smith has been working with hardware for security's s..
|
|
Jayson E. Street - Steal Everything, Kill Everyone, Cause Total Financial Ruin! (Or How I Walked In And Misbehaved)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Street/DEFCON-19-Street-Steal-Everything.pdf This is not a presentation where I talk about how I would get in or the things I might be able to do. This is a talk where I am already in and I show you pictures from actual engagements that I have been on. They say one picture is worth a thousand words I show you how one picture cost a company a million dollars and maybe even a fe....
|
|
Chris "TheSuggmeister" Sumner, alien and Alison B -Weaponizing Cyberpsychology and Subverting Cybervetting for Fun, Profit and Subterfuge
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sumner-Byers-Alien/DEFCON-19-Sumner-Byers-Alien-Weaponizing-Cyberpsychology.pdf Almost everything we do in life leaves a personality footprint and what we do on social networking sites like Facebook is no exception. During this talk we will examine: * What it is possible to determine about someone's personality from their facebook activity * What to look for when you ....
|
|
Martin Holst Swende, Patrik Karlsson - Web Application Analysis With Owasp Hatkit
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Swende-Karlsson/DEFCON-19-Swende-Karlsson-Owasp-Hatkit.pdf The presentation will take a deep dive into two newly released Owasp tools; the Owasp Hatkit Proxy and the Owasp Hatkit Datafiddler. The name Hatkit is an acronym (of sorts) for Http Analysis Toolkit and are tools mainly for people who analyse (hack!) web applications. The tools make extensive use of MongoDB, in particul....
|
|
Mike Tassey, Rich Perkins - Wireless Aerial Surveillance Platform
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Tassey-Perkins/DEFCON-19-Tassey-Perkins-Wireless-Aerial-Surveillance-Platform.pdf Tired of theory? This session has everything you want, big yellow aircraft flown by computers, pounds of highly volatile chemicals, CUDA, 50 Amp electrical circuits and the ability to attack networks, systems and cell phones interactively from a remote location anywhere in the world. We will demo....
|
|
Richard Thieme - Staring into the Abyss: The Dark Side of Crime-fighting, Security, and Professional Intelligence
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Thieme/DEFCON-19-Thieme-Staring-into-the-Abyss-WP.pdf Nothing is harder to see than things we believe so deeply we don't even see them. This is certainly true in the "security space," in which our narratives are self-referential, bounded by mutual self-interest, and characterized by a heavy dose of group-think. That narrative serves as insulation to filter out the most critica....
|
|
Marc Weber Tobias, Matt Fiddler and Tobias Bluzmanis - Insecurity: An Analysis Of Current Commercial And Government Security Lock Designs
-
www.defcon.org
-
14 years ago
-
eng
Lock manufacturers continue to produce insecure designs in both mechanical and electro-mechanical locks. While these devices are designed to provide secure access control to commercial and government facilities, in fact many do not. Recent disclosures with regard to extremely popular push-button locks have led to an expanded investigation into their technology and security by our research team. As a consequence, it appears that mechanical l....
|
|
Ever leave the house without your picks only to find yourself in a situation where you desperately need them? Well, never fear! I'm going to explain how to open everything from cars, to briefcases to safes with objects as common as popsicle sticks and unconventional as palm sanders. Every attack will be fully explained so you understand the underlying mechanisms and how we are taking advantage of mechanical tolerances and design flaws to ow....
|
|
Marketa Trimble - The Future of Cybertravel: Legal Implications of the Evasion of Geolocation
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Trimble/DEFCON-19-Trimble-Cybertravel.ppt.pdf This presentation discusses the current legal status of evasion of geolocation and the potential liability of the user-evader or provider of an evasion tool. The presentation also projects how the law might develop to treat acts of evasion and what challenges the technical community might face in this area. The legal community....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Webb/DEFCON-19-Webb-Runtime-Process-Insemination.pdf Injecting arbitrary code during runtime in linux is a painful process. This presentation discusses current techniques and reveals a new technique not used in other projects. The proposed technique allows for anonymous injection of shared objects, the ability to pwn a process without leaving any physical evidence behind. Libh..
|
|
Matt "scriptjunkie" Weeks - Network Nightmare: Ruling The Nightlife Between Shutdown And Boot With Pxesploit
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Weeks/DEFCON-19-Weeks-Network-Nightmare.pdf The best techniques for exploitation, maintaining access, and owning in general move down the stack, using low-level code to bypass security controls. Take the preboot execution environment and get bios-level access to the hardware from across the network, outside any control of the on-disk operating system. In this presentation I wi....
|
|
Yekaterina Tsipenyuk O'Neil, Erika Chin - Seven Ways to Hang Yourself with Google Android
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/O%27Neil-Chin/DEFCON-19-O%27Neil-Chin-Google-Android.pdf According to Google, Android was designed to give mobile developers "an excellent software platform for everyday users" on which to build rich applications for the growing mobile device market. The power and flexibility of the Android platform are undeniable, but where does it leave developers when it comes to security? ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Weyers/DEFCON-19-Weyers-Key-Impressioning.pdf We've all seen lockpicking explained on several security venues. You might even have tried it yourself. But what if you need to open a lock a number of times? Wouldn't it be great to have an opening technique that would supply you with a working key in the process? A method to do this has existed for quite some time, but until rece....
|
|
Thomas Wilhelm - Staying Connected during a Revolution or Disaster
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Wilhelm/DEFCON-19-Wilhelm-Staying-Connected .pdf During the recent revolutions in Africa and the Middle East, governments have shut down both Internet and Phone services in an attempt to quell communication among demonstrators. In addition, during natural disasters, people have been left without a means of finding out the latest news regarding emergency services. We will discu....
|
|
https://www.defcon.org/html/links/dc-archives/dc-19-archive.html The only thing worse than no security is a false sense of security. And though we know, "you can't win by defense alone", our modern approaches tend to act as though offense and defense are two entirely separate things. Treating security as an issue of quality has gotten us far, however, nearly everyday, some of the largest companies are still being compromised. It's beco....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Arlen/DEFCON-19-Arlen-Nano-Seconds.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Arlen/DEFCON-19-Arlen-Nano-Seconds-WP.pdf There's a brave new frontier for IT Security - a place where "best practices" does not even contemplate the inclusion of a firewall in the network. This frontier is found in the most unlikely of places, where it is presumed that I....
|
|
Mike Arpaia, Ted Reed - Beat to 1337: Creating A Successful University Cyber Defense Organization
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Arpaia-Reed/DEFCON-19-Arpaia-Reed-Beat-to-1337.pdf A university with no prior CTF experience and no students with significant prior information security experience may find competition a daunting task. Most competitions require a large amount of technical knowledge to set up, along with a fair amount of organization. But how are students with no information security knowledge g....
|
|
Mike Arpaia, Ted Reed - Beat to 1337: Creating A Successful University Cyber Defense Organization
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Arpaia-Reed/DEFCON-19-Arpaia-Reed-Beat-to-1337.pdf A university with no prior CTF experience and no students with significant prior information security experience may find competition a daunting task. Most competitions require a large amount of technical knowledge to set up, along with a fair amount of organization. But how are students with no information security knowledge g....
|
|
Mike Arpaia, Ted Reed - Beat to 1337: Creating A Successful University Cyber Defense Organization
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Arpaia-Reed/DEFCON-19-Arpaia-Reed-Beat-to-1337.pdf A university with no prior CTF experience and no students with significant prior information security experience may find competition a daunting task. Most competitions require a large amount of technical knowledge to set up, along with a fair amount of organization. But how are students with no information security knowledge going to....
|
|
Mike Arpaia, Ted Reed - Beat to 1337: Creating A Successful University Cyber Defense Organization
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Arpaia-Reed/DEFCON-19-Arpaia-Reed-Beat-to-1337.pdf A university with no prior CTF experience and no students with significant prior information security experience may find competition a daunting task. Most competitions require a large amount of technical knowledge to set up, along with a fair amount of organization. But how are students with no information security knowledge g....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to ....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to an attacker. T....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to ....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Andrea Barisani, Adam Laurie, Zac Franken & Daniele Bianco - Chip & PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of stolen car....
|
|
Andrea Barisani, Adam Laurie, Zac Franken and Daniele Bianco - Chip and PIN is Definitely Broken
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The author, with 30....
|
|
Bruce "Grymoire" Barnett - Deceptive Hacking: How Misdirection Can Be Used To Steal Information Without Being Detected
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....
|
|
Olivier Bilodeau - Fingerbank - Open DHCP Fingerprints Database
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-FingerBank.pdf The presentation will first take a step back and offer a basic reminder of what passive fingerprinting is and, more precisely, DHCP fingerprinting. Then we will offer defensive and offensive use cases for DHCP fingerprinting. Next, we will cover the goals and resources offered by the new project and some future plans. As part of the announcem....
|
|
Olivier Bilodeau - PacketFence, The Open Source Nac: What We've Done In The Last Two Years
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-PacketFence.pdf Ever heard of PacketFence? It's a free and open source Network Access Control (NAC) software that's been out there since 2005. In the last two years we had several major releases with important new features that makes it an even more compelling solution. Trying to appeal to both attackers and defenders, this presentation will cover all ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of them is....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....
|
|
Sam Bowne - Three Generations of DoS Attacks (with Audience Participation, as Victims)
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....
|