|
Dan Kaminsky - Stack Black Ops: New Concepts for Network Manipulation
-
defcon.org
-
16 years ago
-
eng
Stack Black Ops: New Concepts for Network Manipulation What can your network do? You might be surprised. Layer by layer, this talk will examine previously undocumented and unrealized potential within modern data networks. We will discuss aspects of the newest versions of scanrand, a very high speed port scanner, and the rest of the Paketto Keiretsu. Interesting new techniques will also discussed, including: * Bandwidth Brokering....
|
|
Dan Kaminsky - Stack Black Ops: New Concepts for Network Manipulation
-
defcon.org
-
16 years ago
-
eng
Stack Black Ops: New Concepts for Network Manipulation What can your network do? You might be surprised. Layer by layer, this talk will examine previously undocumented and unrealized potential within modern data networks. We will discuss aspects of the newest versions of scanrand, a very high speed port scanner, and the rest of the Paketto Keiretsu. Interesting new techniques will also discussed, including: * Bandwidth Brokering....
|
|
Dan Kaminsky - Stack Black Ops: New Concepts for Network Manipulation
-
defcon.org
-
16 years ago
-
eng
Stack Black Ops: New Concepts for Network Manipulation What can your network do? You might be surprised. Layer by layer, this talk will examine previously undocumented and unrealized potential within modern data networks. We will discuss aspects of the newest versions of scanrand, a very high speed port scanner, and the rest of the Paketto Keiretsu. Interesting new techniques will also discussed, including: * Bandwidth Brokering....
|
|
Daniel C. Silverstein & Damon McCormick - Increasing The Security Of Your Election By Fixing It
-
defcon.org
-
16 years ago
-
eng
ncreasing The Security Of Your Election By Fixing It In response to the problems that plagued the last United States presidential election, many communities plan to replace existing paper ballot machines with electronic voting systems. Unfortunately, the new systems open up a Pandora's box of security issues that traditional paper ballots do not face. It is difficult to understand the issues because there is a serious lack of data desc....
|
|
HTTP IDS Evasions Revisited HTTP IDS evasions have been prevalent ever since the release of RFP's whisker. But what's been happening since? This presentation addresses the advancement in HTTP IDS evasions since whisker. Some of the specific topics covered will be: * The evolution of protocol-based IDS and signature-based IDS in regards to HTTP evasions. What's the same and what's different? * Latest and greatest obfuscations i....
|
|
HTTP IDS Evasions Revisited HTTP IDS evasions have been prevalent ever since the release of RFP's whisker. But what's been happening since? This presentation addresses the advancement in HTTP IDS evasions since whisker. Some of the specific topics covered will be: * The evolution of protocol-based IDS and signature-based IDS in regards to HTTP evasions. What's the same and what's different? * Latest and greatest obfuscations i....
|
|
Daniel C. Silverstein & Damon McCormick - Increasing The Security Of Your Election By Fixing It
-
defcon.org
-
16 years ago
-
eng
Increasing The Security Of Your Election By Fixing It In response to the problems that plagued the last United States presidential election, many communities plan to replace existing paper ballot machines with electronic voting systems. Unfortunately, the new systems open up a Pandora's box of security issues that traditional paper ballots do not face. It is difficult to understand the issues because there is a serious lack of data des....
|
|
HTTP IDS Evasions Revisited HTTP IDS evasions have been prevalent ever since the release of RFP's whisker. But what's been happening since? This presentation addresses the advancement in HTTP IDS evasions since whisker. Some of the specific topics covered will be: * The evolution of protocol-based IDS and signature-based IDS in regards to HTTP evasions. What's the same and what's different? * Latest and greatest obfuscations i....
|
|
Daniel C. Silverstein & Damon McCormick - Increasing The Security Of Your Election By Fixing It
-
defcon.org
-
16 years ago
-
eng
Increasing The Security Of Your Election By Fixing It In response to the problems that plagued the last United States presidential election, many communities plan to replace existing paper ballot machines with electronic voting systems. Unfortunately, the new systems open up a Pandora's box of security issues that traditional paper ballots do not face. It is difficult to understand the issues because there is a serious lack of data des....
|
|
David Maynor - Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend
-
defcon.org
-
16 years ago
-
eng
Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend The security market is booming. New types of tools are emerging all the time with promises of being able to protect networks better than the last generation.The newest trend is anomly based intrusion detection systems.These systems claim the ability to detect new types of attacks before comprable signature based systems while being able to scale to higher network s....
|
|
David Maynor - Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend
-
defcon.org
-
16 years ago
-
eng
Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend The security market is booming. New types of tools are emerging all the time with promises of being able to protect networks better than the last generation.The newest trend is anomly based intrusion detection systems.These systems claim the ability to detect new types of attacks before comprable signature based systems while being able to scale to higher network s....
|
|
David Maynor - Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend
-
defcon.org
-
16 years ago
-
eng
Why Anomaly Based Intrusion Detection Systems Are A Hackers Best Friend The security market is booming. New types of tools are emerging all the time with promises of being able to protect networks better than the last generation.The newest trend is anomly based intrusion detection systems.These systems claim the ability to detect new types of attacks before comprable signature based systems while being able to scale to higher network s....
|
|
Hacking Web Apps WARNING: The vulnerabilities you are about to see are real. Only the names have been changed to protect the vulnerable. Viewer discretion is advised. Is your web application secure? Many have found out the hard way: encryption and firewalls are not enough. a Since 1996 the instructor has performed security assessments against web-based applications for Fortune 500 companies. The applications audited included c....
|
|
Criminal Copyright Infringement and Warez Trading This talk will discuss criminal copyright infringement and how it applies to warez trading. We will discuss what is legal and what isn’t, who has been prosecuted, why they were prosecuted and what happened to them, and why the law is bad policy. You should expect to leave the talk more knowledgeable about what activities are criminal and how great or small the risks are. Eric Goldm..
|
|
Hacking Web Apps WARNING: The vulnerabilities you are about to see are real. Only the names have been changed to protect the vulnerable. Viewer discretion is advised. Is your web application secure? Many have found out the hard way: encryption and firewalls are not enough. a Since 1996 the instructor has performed security assessments against web-based applications for Fortune 500 companies. The applications audited included c....
|
|
Criminal Copyright Infringement and Warez Trading This talk will discuss criminal copyright infringement and how it applies to warez trading. We will discuss what is legal and what isn’t, who has been prosecuted, why they were prosecuted and what happened to them, and why the law is bad policy. You should expect to leave the talk more knowledgeable about what activities are criminal and how great or small the risks are. Eric Goldm..
|
|
Hacking Web Apps WARNING: The vulnerabilities you are about to see are real. Only the names have been changed to protect the vulnerable. Viewer discretion is advised. Is your web application secure? Many have found out the hard way: encryption and firewalls are not enough. a Since 1996 the instructor has performed security assessments against web-based applications for Fortune 500 companies. The applications audited included c....
|
|
Criminal Copyright Infringement and Warez Trading This talk will discuss criminal copyright infringement and how it applies to warez trading. We will discuss what is legal and what isn’t, who has been prosecuted, why they were prosecuted and what happened to them, and why the law is bad policy. You should expect to leave the talk more knowledgeable about what activities are criminal and how great or small the risks are. Eric Goldm..
|
|
More Embedded Systems The talk focuses on more embedded systems - this time, looking into the mobile world of GSM as well. How can the infrastructures and protocols in the Internet enabled GSM world be used for attacks? This session will give you an introduction to the concepts of WAP and GPRS. Equiped with this knowledge, some interesting applications of these protocols will be presented. Of course, it also covers some funny things yo..
|
|
More Embedded Systems The talk focuses on more embedded systems - this time, looking into the mobile world of GSM as well. How can the infrastructures and protocols in the Internet enabled GSM world be used for attacks? This session will give you an introduction to the concepts of WAP and GPRS. Equiped with this knowledge, some interesting applications of these protocols will be presented. Of course, it also covers some funny things yo..
|
|
More Embedded Systems The talk focuses on more embedded systems - this time, looking into the mobile world of GSM as well. How can the infrastructures and protocols in the Internet enabled GSM world be used for attacks? This session will give you an introduction to the concepts of WAP and GPRS. Equiped with this knowledge, some interesting applications of these protocols will be presented. Of course, it also covers some funny things yo..
|
|
Advanced Network Reconnaissance Techniques Fyodor will present real-life examples of common network and firewall configurations, then demonstrate practical techniques for exploring and mapping those networks. He will cover IDS evasion, "phantom ports", advanced ping sweeps, firewall circumvention, DNS hackery, IPv6, and more using his free Nmap scanner and many other Open Source tools. Fyodor authored the popular Nmap Security Sca....
|
|
Interface Design of Hacking Tools Publicly available computer security tools are often great works of technological expertise. A great deal of effort goes into the technical implementation, often at the expense of the user interface and overall user experience. Designed for all levels of expertise, this talk explores common user interface design techniques that will put a usable front end on computer security tools. A variety of tool....
|
|
Advanced Network Reconnaissance Techniques Fyodor will present real-life examples of common network and firewall configurations, then demonstrate practical techniques for exploring and mapping those networks. He will cover IDS evasion, "phantom ports", advanced ping sweeps, firewall circumvention, DNS hackery, IPv6, and more using his free Nmap scanner and many other Open Source tools. Fyodor authored the popular Nmap Security Sca....
|
|
Interface Design of Hacking Tools Publicly available computer security tools are often great works of technological expertise. A great deal of effort goes into the technical implementation, often at the expense of the user interface and overall user experience. Designed for all levels of expertise, this talk explores common user interface design techniques that will put a usable front end on computer security tools. A variety of tool....
|
|
Advanced Network Reconnaissance Techniques Fyodor will present real-life examples of common network and firewall configurations, then demonstrate practical techniques for exploring and mapping those networks. He will cover IDS evasion, "phantom ports", advanced ping sweeps, firewall circumvention, DNS hackery, IPv6, and more using his free Nmap scanner and many other Open Source tools. Fyodor authored the popular Nmap Security Sca....
|
|
Interface Design of Hacking Tools Publicly available computer security tools are often great works of technological expertise. A great deal of effort goes into the technical implementation, often at the expense of the user interface and overall user experience. Designed for all levels of expertise, this talk explores common user interface design techniques that will put a usable front end on computer security tools. A variety of tool....
|
|
Hack Any Website This session will learn how you can hack any website whatever its protection. The most basic and simple attack against a website is to change the content of one of its pages. When trying to attack a website, one first thinks to attack the web server. But attacking the client could be easier and more powerful. This is what you will see during this session. In one hour, you will understand how to take the full control of....
|
|
Hack Any Website This session will learn how you can hack any website whatever its protection. The most basic and simple attack against a website is to change the content of one of its pages. When trying to attack a website, one first thinks to attack the web server. But attacking the client could be easier and more powerful. This is what you will see during this session. In one hour, you will understand how to take the full control of....
|
|
Hack Any Website This session will learn how you can hack any website whatever its protection. The most basic and simple attack against a website is to change the content of one of its pages. When trying to attack a website, one first thinks to attack the web server. But attacking the client could be easier and more powerful. This is what you will see during this session. In one hour, you will understand how to take the full control of....
|
|
Dumpster Diving: One man's trash... There are few things that yield more information about an individual or organization than their very own trash. This simple fact can be both fun and frightening depending upon which side of the fence you're on. Practiced by hackers for countless years, the act of Dumpster Diving has been an essential tool in the hackers toolkit; and an often overlooked area of an organizations security policies. ....
|
|
Dumpster Diving: One man's trash... There are few things that yield more information about an individual or organization than their very own trash. This simple fact can be both fun and frightening depending upon which side of the fence you're on. Practiced by hackers for countless years, the act of Dumpster Diving has been an essential tool in the hackers toolkit; and an often overlooked area of an organizations security policies. ....
|
|
Dumpster Diving: One man's trash... There are few things that yield more information about an individual or organization than their very own trash. This simple fact can be both fun and frightening depending upon which side of the fence you're on. Practiced by hackers for countless years, the act of Dumpster Diving has been an essential tool in the hackers toolkit; and an often overlooked area of an organizations security policies. ....
|
|
Introducing nmrcOS nmrcOS provides a secure environment for the modern hacker-type to call home, which would help protect the privacy and security of the users of the system. In addition, it provides a portable working environment for the hacker on the go— easy loading on simple hardware, no-nonsense command-line for uber control, yet usable by most people out of the box. Discussion will focus on the history of the project and cur..
|
|
J0hnny Long - Watching the Watchers: Target Exploitation via Public Search Engines
-
defcon.org
-
16 years ago
-
eng
Watching the Watchers: Target Exploitation via Public Search Engines In today's world of all-knowing, all-seeing search engines, it should come as no surprise that very sensitive information lies in the deep recesses of big search engines' data banks. What may come as a surprise, however, is just how much of a search engine's collected data exposes security flaws and vulnerabilities about the crawled sites. In some cases, even aft....
|
|
Introducing nmrcOS nmrcOS provides a secure environment for the modern hacker-type to call home, which would help protect the privacy and security of the users of the system. In addition, it provides a portable working environment for the hacker on the go— easy loading on simple hardware, no-nonsense command-line for uber control, yet usable by most people out of the box. Discussion will focus on the history of the project and cur..
|
|
J0hnny Long - Watching the Watchers: Target Exploitation via Public Search Engines
-
defcon.org
-
16 years ago
-
eng
Watching the Watchers: Target Exploitation via Public Search Engines In today's world of all-knowing, all-seeing search engines, it should come as no surprise that very sensitive information lies in the deep recesses of big search engines' data banks. What may come as a surprise, however, is just how much of a search engine's collected data exposes security flaws and vulnerabilities about the crawled sites. In some cases, even aft....
|
|
Introducing nmrcOS nmrcOS provides a secure environment for the modern hacker-type to call home, which would help protect the privacy and security of the users of the system. In addition, it provides a portable working environment for the hacker on the go— easy loading on simple hardware, no-nonsense command-line for uber control, yet usable by most people out of the box. Discussion will focus on the history of the project and cur..
|
|
J0hnny Long - Watching the Watchers: Target Exploitation via Public Search Engines
-
defcon.org
-
16 years ago
-
eng
Watching the Watchers: Target Exploitation via Public Search Engines In today's world of all-knowing, all-seeing search engines, it should come as no surprise that very sensitive information lies in the deep recesses of big search engines' data banks. What may come as a surprise, however, is just how much of a search engine's collected data exposes security flaws and vulnerabilities about the crawled sites. In some cases, even aft....
|
|
Locking Down Mac OS X Apple's OS X operating system combines BSD Unix with easy-to-use Mac operating system components. This has produced an operating system that natively runs Microsoft Office, is friendly as can be finding you people with which to chat and exchange fileshares with, and yet still runs a command line! Needless to say, it could probably use some lockdown before you want to take it to Def Con, or even to the airport, wit....
|
|
Locking Down Mac OS X Apple's OS X operating system combines BSD Unix with easy-to-use Mac operating system components. This has produced an operating system that natively runs Microsoft Office, is friendly as can be finding you people with which to chat and exchange fileshares with, and yet still runs a command line! Needless to say, it could probably use some lockdown before you want to take it to Def Con, or even to the airport, wit....
|
|
Locking Down Mac OS X Apple's OS X operating system combines BSD Unix with easy-to-use Mac operating system components. This has produced an operating system that natively runs Microsoft Office, is friendly as can be finding you people with which to chat and exchange fileshares with, and yet still runs a command line! Needless to say, it could probably use some lockdown before you want to take it to Def Con, or even to the airport, wit....
|
|
Government IP_TAPPING: Vendors & Techniques Jaya Baloo (CCNP, CISSP) has been working in InfoSec for 5 years, starting at Unisource in The Netherlands. After moving to KPN Telecom, she has worked internationally for the Dutch Telecom Operator in Namibia, Egypt, Germany, and Costa Rica designing secure IP infrastructures for national operators. More recently she has worked in Prague for Czech Telecom on Lawful Interception.
|
|
Jeffrey Prusan - Technical Security Countermeasures: The Real Story Behind Sweeping for Eavesdropping Devices
-
defcon.org
-
16 years ago
-
eng
Technical Security Countermeasures: The Real Story Behind Sweeping for Eavesdropping Devices As a corporate security advisor, former investigator, and TSCM technician, we will dispel the myths behing bugging and wiretapping. We will separate what tappers can and can not do (everything you see in the movies is not always true!!). What companies can do that will realistically protect themselves from eavesdropper and thereby help to prote....
|