|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|
|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|
|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|
|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|
|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|