|
Efstratios Gavas - Asymetric Defense How to fight off the NSA Red Team - Slides
-
www.defcon.org
-
16 years ago
-
eng
Asymmetric Defense: How to Fight Off the NSA Red Team with Five People or Less Efstratios L. Gavas Assistant Professor, United States Merchant Marine Academy The NSA sponsors an annual Cyber Defense Exercise (CDX) to raise awareness of and help develop cyber defense skills in our armed forces. This is the story of how the United Stated Merchant Marine Academy, the smallest of the five undergraduate service academies, has managed to h....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit - Slides
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname - Slides
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments - Slides
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
etd - Dradis Framework Sharing Information Will Get You Root - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
etd - Dradis Framework Sharing Information Will Get You Root - Slides
-
www.defcon.org
-
16 years ago
-
eng
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing - Slides
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Grant Jordan - Stealing Profits from Stock Market Spammers - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Grant Jordan - Stealing Profits from Stock Market Spammers - Slides
-
www.defcon.org
-
16 years ago
-
eng
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Gregory Fleischer - Attacking Tor and the Application Layer - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Gregory Fleischer - Attacking Tor and the Application Layer - Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Haroon Meer and Marco Slaviero - Clobbering the Cloud And Slides
-
www.defcon.org
-
16 years ago
-
eng
Clobbering the Cloud Haroon Meer Technical Director, SensePost Marco Slaviero Cyber Fighter, SensePost Nicholas Arvanitis Senior Security Analyst, SensePost Cloud Computing dominates the headlines these days but like most paradigm changes this introduces new risks and new opportunities for us to consider. Some deep technical research has gone into the underlying technologies (like Virtualization) but to some extent this serves on....
|
|
Haroon Meer and Marco Slaviero - Clobbering the Cloud - Video And Slides
-
www.defcon.org
-
16 years ago
-
eng
Clobbering the Cloud Haroon Meer Technical Director, SensePost Marco Slaviero Cyber Fighter, SensePost Nicholas Arvanitis Senior Security Analyst, SensePost Cloud Computing dominates the headlines these days but like most paradigm changes this introduces new risks and new opportunities for us to consider. Some deep technical research has gone into the underlying technologies (like Virtualization) but to some extent this serves on....
|
|
Haroon Meer and Marco Slaviero - Clobbering the Cloud - Slides
-
www.defcon.org
-
16 years ago
-
eng
Clobbering the Cloud Haroon Meer Technical Director, SensePost Marco Slaviero Cyber Fighter, SensePost Nicholas Arvanitis Senior Security Analyst, SensePost Cloud Computing dominates the headlines these days but like most paradigm changes this introduces new risks and new opportunities for us to consider. Some deep technical research has gone into the underlying technologies (like Virtualization) but to some extent this serves on....
|
|
Iftach Ian Amit - Down the Rabbit Hole Uncovering a Criminal Server
-
www.defcon.org
-
16 years ago
-
eng
Down the Rabbit Hole: Uncovering a Criminal Server Iftach Ian Amit Director, Security Research, Aladdin In this talk I'll cover the research efforts done when we managed to come across a criminally operated server running the latest Neosploit (and other goodies). During the research there have been several crucial points of interest such as the discovery of compromised credentials, getting into the applications used by the crimi....
|
|
Iftach Ian Amit - Down the Rabbit Hole Uncovering a Criminal Server - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Down the Rabbit Hole: Uncovering a Criminal Server Iftach Ian Amit Director, Security Research, Aladdin In this talk I'll cover the research efforts done when we managed to come across a criminally operated server running the latest Neosploit (and other goodies). During the research there have been several crucial points of interest such as the discovery of compromised credentials, getting into the applications used by the crimi....
|
|
Iftach Ian Amit - Down the Rabbit Hole Uncovering a Criminal Server - Slides
-
www.defcon.org
-
16 years ago
-
eng
Down the Rabbit Hole: Uncovering a Criminal Server Iftach Ian Amit Director, Security Research, Aladdin In this talk I'll cover the research efforts done when we managed to come across a criminally operated server running the latest Neosploit (and other goodies). During the research there have been several crucial points of interest such as the discovery of compromised credentials, getting into the applications used by the crimi....
|
|
The Day of the Updates Itzik Kotler Security Operation Center Team Leader, Radware Tomer Bitton Security Researcher, Radware Software updates apply patches or introduce new features to an application. In most cases, the update procedure is conducted in an insecure manner, exposing the updater to execution of malicious code or to manipulation of application data such as anti-virus signatures. This presentation will describe in ....
|
|
Itzik Kotler and Tomer Bitton - The Day of the Updates - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
The Day of the Updates Itzik Kotler Security Operation Center Team Leader, Radware Tomer Bitton Security Researcher, Radware Software updates apply patches or introduce new features to an application. In most cases, the update procedure is conducted in an insecure manner, exposing the updater to execution of malicious code or to manipulation of application data such as anti-virus signatures. This presentation will describe in ....
|
|
Itzik Kotler and Tomer Bitton - The Day of the Updates - Slides
-
www.defcon.org
-
16 years ago
-
eng
The Day of the Updates Itzik Kotler Security Operation Center Team Leader, Radware Tomer Bitton Security Researcher, Radware Software updates apply patches or introduce new features to an application. In most cases, the update procedure is conducted in an insecure manner, exposing the updater to execution of malicious code or to manipulation of application data such as anti-virus signatures. This presentation will describe in ....
|
|
James Myrcurial Arlen and Tiffany Rad - Your Mind Legal Status Rights and Securing Yourself
-
www.defcon.org
-
16 years ago
-
eng
Your Mind: Legal Status, Rights and Securing Yourself James "Myrcurial" Arlen Security Researcher Tiffany Rad President of ELCnetworks, LLC. and Adjunct Professor at University of Southern Maine's Computer Science Department As a participant in the information economy, you no longer exclusively own material originating from your organic brain; you leave a digital trail with your portable device's transmitted communications and when....
|
|
James Myrcurial Arlen and Tiffany Rad - Your Mind Legal Status Rights and Securing Yourself - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Your Mind: Legal Status, Rights and Securing Yourself James "Myrcurial" Arlen Security Researcher Tiffany Rad President of ELCnetworks, LLC. and Adjunct Professor at University of Southern Maine's Computer Science Department As a participant in the information economy, you no longer exclusively own material originating from your organic brain; you leave a digital trail with your portable device's transmitted communications and when....
|
|
James Myrcurial Arlen and Tiffany Rad - Your Mind Legal Status Rights and Securing Yourself - Slides
-
www.defcon.org
-
16 years ago
-
eng
Your Mind: Legal Status, Rights and Securing Yourself James "Myrcurial" Arlen Security Researcher Tiffany Rad President of ELCnetworks, LLC. and Adjunct Professor at University of Southern Maine's Computer Science Department As a participant in the information economy, you no longer exclusively own material originating from your organic brain; you leave a digital trail with your portable device's transmitted communications and when....
|
|
Jason Ostrom and Arjun Sambamoorthy - Advancing Video Application Attacks with Video Interception Recording and Replay
-
www.defcon.org
-
16 years ago
-
eng
Advancing Video Application Attacks with Video Interception, Recording, and Replay Jason Ostrom Director, VIPER Lab Sipera Systems, Inc. Arjun Sambamoorthy Research Engineer, Sipera Systems, Inc. New video applications promise many exciting cost-saving benefits, but they also bring with them a host of security challenges and vulnerabilities. This session applies existing techniques for VoIP eavesdropping towards next generation att....
|
|
Jason Ostrom and Arjun Sambamoorthy - Advancing Video Application Attacks with Video Interception Recording and Replay - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Advancing Video Application Attacks with Video Interception, Recording, and Replay Jason Ostrom Director, VIPER Lab Sipera Systems, Inc. Arjun Sambamoorthy Research Engineer, Sipera Systems, Inc. New video applications promise many exciting cost-saving benefits, but they also bring with them a host of security challenges and vulnerabilities. This session applies existing techniques for VoIP eavesdropping towards next generation att....
|
|
Jason Ostrom and Arjun Sambamoorthy - Advancing Video Application Attacks with Video Interception Recording and Replay - Slides
-
www.defcon.org
-
16 years ago
-
eng
Advancing Video Application Attacks with Video Interception, Recording, and Replay Jason Ostrom Director, VIPER Lab Sipera Systems, Inc. Arjun Sambamoorthy Research Engineer, Sipera Systems, Inc. New video applications promise many exciting cost-saving benefits, but they also bring with them a host of security challenges and vulnerabilities. This session applies existing techniques for VoIP eavesdropping towards next generation att....
|
|
Cloud Security in Map/Reduce Jason Schlesinger Security Researcher This presentation is an overview of the operations principles of Map/Reduce and Hadoop with examples of typical implementation in a business environment. It points out significant security issues that now exist and others that will certainly arise. The presentation also offers suggestions for improving security in existing installations, and presents improvements to p..
|