|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
Jayson E. Street - Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering
-
www.defcon.org
-
15 years ago
-
eng
There are new threats arising every day. The problem is there has been a vulnerability in the system that has not been patched since the first computer was created by Humans! As the network perimeter hardens and the controls on the desktop tightens. Hackers are going back to the basics and getting through the firewall by going through the front door. They are bypassing the IPS and IDS simply by bypassing the receptionist. We look ....
|
|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|
|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|
|
You downloaded google toolbar because it came with Adobe, or you are a a Google fanboy. You started using it to store your bookmarks because you're too lame to rsync them like real man. Little do you know that google is selling you out to your corporate security staff. They now know about the midget porn...the porn you bookmarked at home, but never view at work. Yes *that* porn Jeff Bryner has 20 years of experience integrating systems..
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl - The Law of Laptop Search and Seizure
-
www.defcon.org
-
15 years ago
-
eng
This talk will teach attendees about their legal rights in information stored on their laptops, including when crossing the United States border. We will answer questions such as: What do the police need to do to seize your laptop? Can the U.S. government force you to turn over your password during a border search? Do you have constitutional rights in email and other data stored in the cloud? What happens when the government attempts to for....
|
|
Jennifer Granick & Matt Zimmerman - Legal Developments in Hardware Hacking
-
www.defcon.org
-
15 years ago
-
eng
Hardware hacking raises some novel legal issues This presentation will discuss recent updates in the law that hardware hackers need to know. Topics will include updates on phone unlocking and jailbreaking following the Digital Millennium Copyright Act rulemaking and reverse engineering law. We will also discuss a case in California that will decide whether it's legal for a company to automate user access to her Facebook's data without using....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
Jeongwook Oh - ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically
-
www.defcon.org
-
15 years ago
-
eng
This is a new methods to expedite the speed of binary diffing process. Most of the time in analyzing security patches are spent in finding the patched parts of the binary. In some cases one patch contains multiple patches and feature updates. The mixed patches will make the analysis very difficult and time consuming. That's where our new security patch recognizing technology kicks in. We're presenting general signature based security patch ....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
SCADA systems are just as vulnerable to attack today than they were ten years ago. The lack of security awareness by SCADA software vendors, combined with the rush of hacking these systems, make them very attractive to hackers today. The focus of this presentation will be showing the disconnect between SCADA software and secure programming. There will be a live demonstration of Sploitware, a framework dedicated to vulnerability analysis of ..
|
|
In 2008, Eric Rachner was playing a round of Urban Golf with friends in Seattle. When an errant foam ball hit by another player struck a passer-by, the police were called. Eric was standing on the sidewalk minding his own business, and arrested for 'Obstruction' for refusing to identify himself to police. Refusing to back down, Eric took his case to court where it was ultimately dismissed. Today he continues to fight against the Seattle Pol....
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover most of the basics and some of the advanced principles/procedures to how drug screening works. Areas of the subject that will be covered will be the legality of drugs, the legality of drug testing, methods of drug testing, sample types, and reliability. Jimi Fiekert's bio: I am a graduate of Cincinnati Technical College with a degree in Medical Laboratory Technician (MLT), and certified by the American Society of C..
|
|
This talk will cover three different methods of function hooking for Mac OSX and Linux. The talk will begin by describing useful bits of Intel64 assembly followed up with 3 different binary rewriting techniques to hook a range of different functions, including some inlined functions, too. We'll finish up with a demo of two nice things that these techniques make possible (a memory profiler and a function call tracer), and one slightly more e..
|