|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
The most fundamental difference between hash and nested loop joins
-
tanelpoder.com
-
15 years ago
-
eng
Basically the most fundamental (or biggest or most important) difference between nested loop and hash joins is that: Hash joins can not look up rows from the inner (probed) row source based on values retrieved from the outer (driving) row source, nested loops can. In other words, when joining table A and B (A is driving table, B is the probed table), then a nested loop join can take 1st row from A and perform a lookup to B using that ..
|
|
The most fundamental difference between hash and nested loop joins
-
tanelpoder.com
-
15 years ago
-
eng
Basically the most fundamental (or biggest or most important) difference between nested loop and hash joins is that: Hash joins can not look up rows from the inner (probed) row source based on values retrieved from the outer (driving) row source, nested loops can. In other words, when joining table A and B (A is driving table, B is the probed table), then a nested loop join can take 1st row from A and perform a lookup to B using that ..
|
|
Sometimes I’m asked to write or speak about something with very little preparation. In these situations, I need a tool that can help me: Organize my thoughts quickly Prioritize the wheat before the chaff Maintain a coherent train of thought I find a very useful structure for archiving this to be what I call “three-by-three”: Three main points with three subpoints each. Forcing myself to keep to a structure will make my thoughts flow more qu..
|
|
A while back, I was poking around LLVM bugs, and discovered, to my surprise, that LLVM doesn’t support the va_arg intrinsic, used by functions to accept multiple arguments, at all on amd64. It turns out that clang and llvm-gcc, the compilers that backend to LLVM, have their own implementations in the frontend, so this isn’t as big a deal as it might sound, but it was still a surprise to me.
|
|
A while back, I was poking around LLVM bugs, and discovered, to my surprise, that LLVM doesn’t support the va_arg intrinsic, used by functions to accept multiple arguments, at all on amd64. It turns out that clang and llvm-gcc, the compilers that backend to LLVM, have their own implementations in the frontend, so this isn’t as big a deal as it might sound, but it was still a surprise to me.
|
|
I have been working self-employed for s IT Solutions since 1 March 2010; from 1 September I’m salaried there. (I shall still be doing bug-fixing for my old customers, consultancy, and perhaps some smaller new development projects on the side. This is explicitly allowed in my employment contract.) s IT Solutions is the IT provider for Erste Bank and the Sparkasse Group . My role is in the team doing the Internet presence of those banks ..
|
|
How pair programming and test-driven development looks in real life
-
jhannes.github.io
-
15 years ago
-
eng
Pair programming and test-driven development are some of the practices that are most often talked about and least often actually understood. So I’ve decided to undertake the task to teach myself to program a simple, yet realistic problem with a pair programming partner. The goal is to create an entertaining and realistic performance that portrays what it feels like to work like this. I’ve been extremely lucky. I’ve found not one, but two pr..
|
|
The below is a quick Python snippet which I use on a day to day basis for weeks, then promptly forget. Essentially its reading from standard input and then doing something with it. Very useful when you are trying to process data on the command line and have forgotten how to use awk/sed properly and grep has run out of steam. import sys import re for line in sys . stdin: values = line . split( ',' ) pri..
|
|
If you are developing an application for the Android platform, and you need to interact with the Twitter API, you now have to use OAuth to authenticate the user. In this article, we will have a look on how you can do that. What is OAuth? OAuth is a way of accessing a user’s data (e.g. tweets) without asking for the user’s username and password. Your application opens the Twitter website which will ask the user if they want to allow you to....
|
|
If you are developing an application for the Android platform, and you need to interact with the Twitter API, you now have to use OAuth to authenticate the user. In this article, we will have a look on how you can do that. What is OAuth? OAuth is a way of accessing a user’s data (e.g. tweets) without asking for the user’s username and password. Your application opens the Twitter website which will ask the user if they want to allow you to....
|
|
I'm a very new user of Git. I've been using it for some time to download and install repositories, like most people, but didn't use it for source control yet. Recently I've started using it, though, so I've been bumping into small problems along the way. One problem I've had was with trying to find out how to keep certain files out of a repository. I had tried Googling a few terms, but that only brought up results for actually removing a fi..
|
|
I ran across this post yesterday, by css-tricks.com. They had a little UI design competition where they asked participants to design and develop a UI for editing and deleting items of a list. It's a cool idea for a competition and you can read the whole thing here: https://css-tricks.com/ui-pattern-ideas-list-with-functions/ I chimed in at the comments, but realized quickly that this should become a blog post by itself.
|
|
I'm a very new user of Git. I've been using it for some time to download and install repositories, like most people, but didn't use it for source control yet. Recently I've started using it, though, so I've been bumping into small problems along the way. One problem I've had was with trying to find out how to keep certain files out of a repository. I had tried Googling a few terms, but that only brought up results for actually removing a fi..
|
|
I ran across this post yesterday, by css-tricks.com. They had a little UI design competition where they asked participants to design and develop a UI for editing and deleting items of a list. It's a cool idea for a competition and you can read the whole thing here: https://css-tricks.com/ui-pattern-ideas-list-with-functions/ I chimed in at the comments, but realized quickly that this should become a blog post by itself.
|
|
According to Wikipedia, stenography or shorthand is “is an abbreviated symbolic writing method that increases speed or brevity of writing as compared to a normal method of writing a language”. Just as a stenographer learns to take down information really fast, a good programmer can learn to write code really fast by taking advantage of his or her tools. In this post I’ll show you my secret code stenography tricks.
|
|
After the fuss of the last two weeks because of CVE-2010-3081 and CVE-2010-3301, I decided to take a look at a handful of the high-profile privilege escalation vulnerabilities in Linux from the last few years. So, here's a summary of the ones I picked out. There are also a large number of smaller ones, like an AF\_CAN exploit, or the l2cap overflow in the Bluetooth subsystem, that didn't get as much publicity, because they were found more q..
|
|
After the fuss of the last two weeks because of CVE-2010-3081 and CVE-2010-3301, I decided to take a look at a handful of the high-profile privilege escalation vulnerabilities in Linux from the last few years. So, here's a summary of the ones I picked out. There are also a large number of smaller ones, like an AF\_CAN exploit, or the l2cap overflow in the Bluetooth subsystem, that didn't get as much publicity, because they were found more q..
|
|
Comment on Tiffany Shlain’s The Tribe by Tweets that mention Tiffany Shlain’s The Tribe | BillSaysThis -- Topsy.com
-
billsaysthis.com
-
15 years ago
-
eng
This post was mentioned on Twitter by billsaysthis, Tiffany Shlain. Tiffany Shlain said: Don't you think you could encourage people to watch it on itunes? RT @billsaysthis: :)http://bit.ly/bKVG58 [...]
|
|
Malicious Logik Playing: The Pool on Friday, 6pm-7pm No residencies or national exposure...Just trying to get a chance to rock the "house" at DEFCON bringing a little different flavor of choons...I got white house, black house, Spanish house, yellow house, I got hot house, cold house, I got wet house, I got smelly house, i got hairy house, bloody house, i got snappin' house, i got silk house, velvet house, Naugahyde house, i even go..
|
|
Miss Jackalope DefCon | 303 | Exotic Liability | Rinsetigator Radio Playing: The Cyberpunk Gala (Capri101/102) on Saturday, 12am-1am (Sunday Morning) Miss Jackalope has been kicking ass and taking names at Defcon for a very long time. She's played on Rinstigator radio on UK based internet radio stations and her loves are jungle, breakbeat, techno, making new friends, mocha coffee, comic books, and teaching lockpicking. Last sigh..
|