|
Scott Moulton - RAID Recovery Recover Your PORN By Sight and Sound - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
RAID Recovery: Recover your PORN by Sight and Sound Scott Moulton Forensic Strategy Services, LLC. / System Specialist This talk will focus on RAID reassembly. In both Forensics and Data Recovery it is common for there to be PORN not only in Pictures but also in Sound Files and Video Files. The goal is $100 or less, figure out how to reconstruct RAID 0 and RAID 5 arrays using the PORN on the array to help identify the correct order o..
|
|
Scott Moulton - RAID Recovery Recover Your PORN By Sight and Sound - Slides
-
www.defcon.org
-
16 years ago
-
eng
RAID Recovery: Recover your PORN by Sight and Sound Scott Moulton Forensic Strategy Services, LLC. / System Specialist This talk will focus on RAID reassembly. In both Forensics and Data Recovery it is common for there to be PORN not only in Pictures but also in Sound Files and Video Files. The goal is $100 or less, figure out how to reconstruct RAID 0 and RAID 5 arrays using the PORN on the array to help identify the correct order o..
|
|
Sean Boyce - Design and Implementation of a Quantum True number Generator
-
www.defcon.org
-
16 years ago
-
eng
Design and Implementation of a Quantum True Random Number Generator Sean Boyce Security Researcher The problem of generating "reasonable" approximations to random numbers has been solved quite some time ago... but this talk is not for reasonable people. Generating true random numbers with a deterministic system is impossible; and so we must drink deeply from the raw, godless chaos of quantum physics. This talk will cover the var....
|
|
Sean Boyce - Design and Implementation of a Quantum True number Generator - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Design and Implementation of a Quantum True Random Number Generator Sean Boyce Security Researcher The problem of generating "reasonable" approximations to random numbers has been solved quite some time ago... but this talk is not for reasonable people. Generating true random numbers with a deterministic system is impossible; and so we must drink deeply from the raw, godless chaos of quantum physics. This talk will cover the var....
|
|
Sean Boyce - Design and Implementation of a Quantum True number Generator - Slides
-
www.defcon.org
-
16 years ago
-
eng
Design and Implementation of a Quantum True Random Number Generator Sean Boyce Security Researcher The problem of generating "reasonable" approximations to random numbers has been solved quite some time ago... but this talk is not for reasonable people. Generating true random numbers with a deterministic system is impossible; and so we must drink deeply from the raw, godless chaos of quantum physics. This talk will cover the var....
|
|
Sean Taylor - Binary Obfuscation from the Top Down Obfuscating Executables Without Writing Assembly
-
www.defcon.org
-
16 years ago
-
eng
Binary Obfuscation from the Top-Down: Obfuscating Executables Without Writing Assembly Sean "Frank^2" Taylor Security Engineer, Rapid7 Binary obfuscation is commonly applied in malware and by software vendors in order to frustrate the efforts of reverse engineers to understand the underlying code. A common misconception is one must be a master of assembly in order to properly obfuscate a binary. However, with knowledge of compiler op....
|
|
Sean Taylor - Binary Obfuscation from the Top Down Obfuscating Executables Without Writing Assembly - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Binary Obfuscation from the Top-Down: Obfuscating Executables Without Writing Assembly Sean "Frank^2" Taylor Security Engineer, Rapid7 Binary obfuscation is commonly applied in malware and by software vendors in order to frustrate the efforts of reverse engineers to understand the underlying code. A common misconception is one must be a master of assembly in order to properly obfuscate a binary. However, with knowledge of compiler op....
|
|
Sean Taylor - Binary Obfuscation from the Top Down Obfuscating Executables Without Writing Assembly - Slides
-
www.defcon.org
-
16 years ago
-
eng
Binary Obfuscation from the Top-Down: Obfuscating Executables Without Writing Assembly Sean "Frank^2" Taylor Security Engineer, Rapid7 Binary obfuscation is commonly applied in malware and by software vendors in order to frustrate the efforts of reverse engineers to understand the underlying code. A common misconception is one must be a master of assembly in order to properly obfuscate a binary. However, with knowledge of compiler op....
|
|
Shawn Moyer and Nathan Hamiel - Weaponizing the Web New Attacks on User Generated Content
-
www.defcon.org
-
16 years ago
-
eng
Weaponizing the Web: New Attacks on User-generated Content Shawn Moyer Nathan Hamiel Ultimately, basing the value proposition of your site on user-generated and external content is a kind of variant on Russian Roulette, where in every turn the gun is pointed at your head, regardless of the number of players. You may win most of the time, but eventually a bullet is going to find its way into the chamber with your name on it. We....
|
|
Shawn Moyer and Nathan Hamiel - Weaponizing the Web New Attacks on User Generated Content - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Weaponizing the Web: New Attacks on User-generated Content Shawn Moyer Nathan Hamiel Ultimately, basing the value proposition of your site on user-generated and external content is a kind of variant on Russian Roulette, where in every turn the gun is pointed at your head, regardless of the number of players. You may win most of the time, but eventually a bullet is going to find its way into the chamber with your name on it. We....
|
|
Shawn Moyer and Nathan Hamiel - Weaponizing the Web New Attacks on User Generated Content - Slides
-
www.defcon.org
-
16 years ago
-
eng
Weaponizing the Web: New Attacks on User-generated Content Shawn Moyer Nathan Hamiel Ultimately, basing the value proposition of your site on user-generated and external content is a kind of variant on Russian Roulette, where in every turn the gun is pointed at your head, regardless of the number of players. You may win most of the time, but eventually a bullet is going to find its way into the chamber with your name on it. We....
|
|
Death of Anonymous Travel Sherri Davidoff Philosecurity Worldwide, people who use cars, buses, trains, and carry cell phones are tracked in increasingly centralized corporate and government databases. This capability is still in its infancy, and has been facilitated by payment systems which are linked to identification and refer to centralized electronic databases. Mass tracking and surveillance capabilities have arisen organica....
|
|
Sherri Davidoff - Death of Anonymous Travel - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Death of Anonymous Travel Sherri Davidoff Philosecurity Worldwide, people who use cars, buses, trains, and carry cell phones are tracked in increasingly centralized corporate and government databases. This capability is still in its infancy, and has been facilitated by payment systems which are linked to identification and refer to centralized electronic databases. Mass tracking and surveillance capabilities have arisen organica....
|
|
Death of Anonymous Travel Sherri Davidoff Philosecurity Worldwide, people who use cars, buses, trains, and carry cell phones are tracked in increasingly centralized corporate and government databases. This capability is still in its infancy, and has been facilitated by payment systems which are linked to identification and refer to centralized electronic databases. Mass tracking and surveillance capabilities have arisen organica....
|
|
FOE -- Feeding Controversial News to Censored Countries (Without Using Proxy Servers) Sho Ho Software Engineer, Broadcasting Board of Governors Certain countries are banning their Internet users from accessing websites that are deemed inappropriate by their officials. News organizations' websites are commonly blocked by these countries, and there are little these organizations can do to reach their audience inside those countries. FO....
|
|
Sho Ho - FOE Feeding Controversial News to Censored Countries - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
FOE -- Feeding Controversial News to Censored Countries (Without Using Proxy Servers) Sho Ho Software Engineer, Broadcasting Board of Governors Certain countries are banning their Internet users from accessing websites that are deemed inappropriate by their officials. News organizations' websites are commonly blocked by these countries, and there are little these organizations can do to reach their audience inside those countries. FO....
|
|
Sho Ho - FOE Feeding Controversial News to Censored Countries - Slides
-
www.defcon.org
-
16 years ago
-
eng
FOE -- Feeding Controversial News to Censored Countries (Without Using Proxy Servers) Sho Ho Software Engineer, Broadcasting Board of Governors Certain countries are banning their Internet users from accessing websites that are deemed inappropriate by their officials. News organizations' websites are commonly blocked by these countries, and there are little these organizations can do to reach their audience inside those countries. FO....
|
|
Stephen Afterburn Janansky and Nick Waite - Hardware Trojans Infiltrating the Faraday Cage
-
www.defcon.org
-
16 years ago
-
eng
Hardware Trojans: Infiltrating the Faraday Cage Stephen 'afterburn' Janansky CVORG, University of Delaware Nick Waite CVORG, University of Delaware Last year we presented some hardware trojans as a proof of concept for side-channel data exfiltration attack. Pretty blinking lights are sweet, but this time we wanted to give the hungry crowd something more crunchy to bite into. Namely, that age-old problem of how to get data in and ou....
|
|
Stephen Afterburn Janansky and Nick Waite - Hardware Trojans Infiltrating the Faraday Cage - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Hardware Trojans: Infiltrating the Faraday Cage Stephen 'afterburn' Janansky CVORG, University of Delaware Nick Waite CVORG, University of Delaware Last year we presented some hardware trojans as a proof of concept for side-channel data exfiltration attack. Pretty blinking lights are sweet, but this time we wanted to give the hungry crowd something more crunchy to bite into. Namely, that age-old problem of how to get data in and ou....
|
|
Stephen Afterburn Janansky and Nick Waite - Hardware Trojans Infiltrating the Faraday Cage - Slides
-
www.defcon.org
-
16 years ago
-
eng
Hardware Trojans: Infiltrating the Faraday Cage Stephen 'afterburn' Janansky CVORG, University of Delaware Nick Waite CVORG, University of Delaware Last year we presented some hardware trojans as a proof of concept for side-channel data exfiltration attack. Pretty blinking lights are sweet, but this time we wanted to give the hungry crowd something more crunchy to bite into. Namely, that age-old problem of how to get data in and ou....
|
|
Personal Survival Preparedness Steve Dunker Associate Professor, Northeastern State University Kristie Dunker The Swag Assistant When the sewage hits the oscillating blades of death, will you be ready? A Las Vegas Survival Scenario will be presented to the audience at the start of the lecture. This talk will concentrate on disaster preparedness at the individual and/or family level. General overall preparedness will be covered as w..
|
|
Steve and Kristie Dunker - Personal Disaster Prepardness - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Personal Survival Preparedness Steve Dunker Associate Professor, Northeastern State University Kristie Dunker The Swag Assistant When the sewage hits the oscillating blades of death, will you be ready? A Las Vegas Survival Scenario will be presented to the audience at the start of the lecture. This talk will concentrate on disaster preparedness at the individual and/or family level. General overall preparedness will be covered as w..
|
|
Steve and Kristie Dunker - Personal Disaster Prepardness - Slides
-
www.defcon.org
-
16 years ago
-
eng
Personal Survival Preparedness Steve Dunker Associate Professor, Northeastern State University Kristie Dunker The Swag Assistant When the sewage hits the oscillating blades of death, will you be ready? A Las Vegas Survival Scenario will be presented to the audience at the start of the lecture. This talk will concentrate on disaster preparedness at the individual and/or family level. General overall preparedness will be covered as w..
|
|
Summit Siddharth - The Making of the Second SQL Injection Worm
-
www.defcon.org
-
16 years ago
-
eng
The Making of the second SQL injection Worm Sumit Siddharth IT Security Consultant The "turbo" talk will focus on exploiting SQL injections in web applications with oracle back-end. Mostly exploiting Oracle sql injections in web applications is considered to be restricted to extraction of data only. Oracle database does not offer hacker friendly functionalities such as openrowset or xp_cmdshell for privilege escalation and O.S code e....
|
|
Summit Siddharth - The Making of the Second SQL Injection Worm - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
The Making of the second SQL injection Worm Sumit Siddharth IT Security Consultant The "turbo" talk will focus on exploiting SQL injections in web applications with oracle back-end. Mostly exploiting Oracle sql injections in web applications is considered to be restricted to extraction of data only. Oracle database does not offer hacker friendly functionalities such as openrowset or xp_cmdshell for privilege escalation and O.S code e....
|
|
Summit Siddharth - The Making of the Second SQL Injection Worm - Slides
-
www.defcon.org
-
16 years ago
-
eng
The Making of the second SQL injection Worm Sumit Siddharth IT Security Consultant The "turbo" talk will focus on exploiting SQL injections in web applications with oracle back-end. Mostly exploiting Oracle sql injections in web applications is considered to be restricted to extraction of data only. Oracle database does not offer hacker friendly functionalities such as openrowset or xp_cmdshell for privilege escalation and O.S code e....
|
|
Thomas Holt and Panel - Identifying Exploring and Predicting Threats in the Russian Hacker Community
-
www.defcon.org
-
16 years ago
-
eng
Identifying, Exploring, and Predicting Threats in the Russian Hacker Community Dr. Thomas J. Holt Assistant Professor, School of Criminal Justice, Michigan State University Dr. Max Kilger The Honeynet Project Dr. Debora Strumsky The University of North Carolina at Charlotte Dr. Olga Smirnova The University of North Carolina at Charlotte A great deal of research has focused on the malicious software and attack tools generated by....
|
|
Thomas Holt and Panel - Identifying Exploring and Predicting Threats in the Russian Hacker Community - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Identifying, Exploring, and Predicting Threats in the Russian Hacker Community Dr. Thomas J. Holt Assistant Professor, School of Criminal Justice, Michigan State University Dr. Max Kilger The Honeynet Project Dr. Debora Strumsky The University of North Carolina at Charlotte Dr. Olga Smirnova The University of North Carolina at Charlotte A great deal of research has focused on the malicious software and attack tools generated by....
|
|
Thomas Holt and Panel - Identifying Exploring and Predicting Threats in the Russian Hacker Community - Slides
-
www.defcon.org
-
16 years ago
-
eng
Identifying, Exploring, and Predicting Threats in the Russian Hacker Community Dr. Thomas J. Holt Assistant Professor, School of Criminal Justice, Michigan State University Dr. Max Kilger The Honeynet Project Dr. Debora Strumsky The University of North Carolina at Charlotte Dr. Olga Smirnova The University of North Carolina at Charlotte A great deal of research has focused on the malicious software and attack tools generated by....
|
|
Hacking WITH the iPod Touch Thomas Wilhelm Sr. Network & Information Security Engineer; Adjunct Processor There has been plenty of news about hacking into the iPod Touch, but what about using the iTouch as a hacking platform? This talk will discuss how to convert the iTouch into a PenTest device, describe available tools, and talk about potential uses for the iTouch as a social engineering tool to provide unauthorized access within a....
|
|
Thomas Wilhelm - Hacking with the iPod Touch - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Hacking WITH the iPod Touch Thomas Wilhelm Sr. Network & Information Security Engineer; Adjunct Processor There has been plenty of news about hacking into the iPod Touch, but what about using the iTouch as a hacking platform? This talk will discuss how to convert the iTouch into a PenTest device, describe available tools, and talk about potential uses for the iTouch as a social engineering tool to provide unauthorized access within a....
|
|
Hacking WITH the iPod Touch Thomas Wilhelm Sr. Network & Information Security Engineer; Adjunct Processor There has been plenty of news about hacking into the iPod Touch, but what about using the iTouch as a hacking platform? This talk will discuss how to convert the iTouch into a PenTest device, describe available tools, and talk about potential uses for the iTouch as a social engineering tool to provide unauthorized access within a....
|
|
Tom Eston and Kevin Johnson - Social Zombies Your Friends want to Eat Your Brains
-
www.defcon.org
-
16 years ago
-
eng
Social Zombies: Your Friends Want to Eat Your Brains Tom Eston Social Media Security Researcher Kevin Johnson Senior Security Analyst, InGuardians In Social Zombies: Your Friends want to eat Your Brains, Tom Eston and Kevin Johnson explore the various concerns related to malware delivery through social network sites. Ignoring the FUD and confusion being sowed today, this presentation will examine the risks and then present tools th....
|
|
Tom Eston and Kevin Johnson - Social Zombies Your Friends want to Eat Your Brains - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Social Zombies: Your Friends Want to Eat Your Brains Tom Eston Social Media Security Researcher Kevin Johnson Senior Security Analyst, InGuardians In Social Zombies: Your Friends want to eat Your Brains, Tom Eston and Kevin Johnson explore the various concerns related to malware delivery through social network sites. Ignoring the FUD and confusion being sowed today, this presentation will examine the risks and then present tools th....
|
|
Tom Eston and Kevin Johnson - Social Zombies Your Friends want to Eat Your Brains - Slides
-
www.defcon.org
-
16 years ago
-
eng
Social Zombies: Your Friends Want to Eat Your Brains Tom Eston Social Media Security Researcher Kevin Johnson Senior Security Analyst, InGuardians In Social Zombies: Your Friends want to eat Your Brains, Tom Eston and Kevin Johnson explore the various concerns related to malware delivery through social network sites. Ignoring the FUD and confusion being sowed today, this presentation will examine the risks and then present tools th....
|
|
An Open JTAG Debugger Travis Goodspeed Engineer of Superior Buckles, Goodspeed & Gourneau While it's simple enough to build a "Wiggler" JTAG adapter for the PC parallel port, there is very little open hardware for performing high-speed programming of JTAG devices by USB. This lecture introduces the GoodFET, an open source USB JTAG adapter which can be reflashed to support the programming and debugging of any number of chips. Both har....
|
|
An Open JTAG Debugger Travis Goodspeed Engineer of Superior Buckles, Goodspeed & Gourneau While it's simple enough to build a "Wiggler" JTAG adapter for the PC parallel port, there is very little open hardware for performing high-speed programming of JTAG devices by USB. This lecture introduces the GoodFET, an open source USB JTAG adapter which can be reflashed to support the programming and debugging of any number of chips. Both har....
|
|
An Open JTAG Debugger Travis Goodspeed Engineer of Superior Buckles, Goodspeed & Gourneau While it's simple enough to build a "Wiggler" JTAG adapter for the PC parallel port, there is very little open hardware for performing high-speed programming of JTAG devices by USB. This lecture introduces the GoodFET, an open source USB JTAG adapter which can be reflashed to support the programming and debugging of any number of chips. Both har....
|
|
Locally Exploiting Wireless Sensors Travis Goodspeed Engineer of Superior Buckles, Goodspeed and Gourneau Wireless sensors are often built with a microcontroller and a radio chip, connected only by a SPI bus. The radio, not the MCU, is responsible for symmetrical cryptography of each packet. When the key is loaded, it is sent as cleartext over the SPI bus, and an attacker with local access can steal the key using a few syringe probes....
|
|
Travis Goodspeed - Locally Exploiting Wireless Sensors - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Locally Exploiting Wireless Sensors Travis Goodspeed Engineer of Superior Buckles, Goodspeed and Gourneau Wireless sensors are often built with a microcontroller and a radio chip, connected only by a SPI bus. The radio, not the MCU, is responsible for symmetrical cryptography of each packet. When the key is loaded, it is sent as cleartext over the SPI bus, and an attacker with local access can steal the key using a few syringe probes....
|
|
Travis Goodspeed - Locally Exploiting Wireless Sensors - Slides
-
www.defcon.org
-
16 years ago
-
eng
Locally Exploiting Wireless Sensors Travis Goodspeed Engineer of Superior Buckles, Goodspeed and Gourneau Wireless sensors are often built with a microcontroller and a radio chip, connected only by a SPI bus. The radio, not the MCU, is responsible for symmetrical cryptography of each packet. When the key is loaded, it is sent as cleartext over the SPI bus, and an attacker with local access can steal the key using a few syringe probes....
|
|
Search And Seizure Explained - They Took My Laptop! Tyler Pitchford, Esq. C.T.O. - Digome, LLC. An overview of recent developments surrounding the Fourth and Fifth Amendments of the United States Constitution and their impact upon privacy conscious computer professionals. The presentation includes discussions on the United States Constitution, Federal Statutes, Administrative decisions, and, most importantly, the case laws that inter....
|
|
Tyler Pitchford - Search and Seizure Explained - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Search And Seizure Explained - They Took My Laptop! Tyler Pitchford, Esq. C.T.O. - Digome, LLC. An overview of recent developments surrounding the Fourth and Fifth Amendments of the United States Constitution and their impact upon privacy conscious computer professionals. The presentation includes discussions on the United States Constitution, Federal Statutes, Administrative decisions, and, most importantly, the case laws that inter....
|
|
Search And Seizure Explained - They Took My Laptop! Tyler Pitchford, Esq. C.T.O. - Digome, LLC. An overview of recent developments surrounding the Fourth and Fifth Amendments of the United States Constitution and their impact upon privacy conscious computer professionals. The presentation includes discussions on the United States Constitution, Federal Statutes, Administrative decisions, and, most importantly, the case laws that inter....
|