|
Using a Balloon as an aerial network surveillance platform, a.k.a. "WarBallooning" is an idea that evolved as a natural progression out of my Rocket-based experiment @ Defcon 14 entitled, "WarRocketing - Network Stumbling 50 sq. miles in <60 seconds." Interestingly, after my presentation in 2006, many in the wireless community discussed Balloon-based network discovery, notably CoWF & Slashdot. But, alas, like many great concepts in the....
|
|
Robert Ricks: New Tool for SQL Injection with DNS Exfiltration
-
www.defcon.org
-
19 years ago
-
eng
For years people have been warned that blind SQL injection is a problem, yet there are a multitude of vulnerable websites out there to this day. Perhaps people don't realize that these vulnerabilities are very real. The current state of the art tools are Absinthe and SQL Brute for exploiting blind SQL injection. DNS exfiltration has been proposed as a method of reaching previously unassailable blind SQL injection access points. We have crea....
|
|
There have been a number of exciting bugs and design flaws in Tor over the years, with effects ranging from complete anonymity compromise to remote code execution. Some of them are our fault, and some are the fault of components (libraries, browsers, operating systems) that we trusted. Further, the academic research community has been coming up with increasingly esoteric --- and increasingly effective! --- attacks against all anonymity desi....
|
|
Ryan Trost: Evade IDS/IPS Systems using Geospatial Threat Detection
-
www.defcon.org
-
19 years ago
-
eng
IDS/IPS systems are becoming more and more advanced and geocoding is adding another layer of intelligence to try and defend against a company's vulnerabilities. Learn how to evade complex geospatial threat detection countermeasures. Most crackers use zombie machines to launch professional attacks...but zombies even leave geographic fingerprints that are easily picked up by pattern recognition algorithms. Learn how to take professional attac....
|
|
Sandy "Mouse" Clark: Climbing Everest: An Insider's Look at one state's Voting Systems
-
www.defcon.org
-
19 years ago
-
eng
Hanging Chads, Hopping votes, Flipped votes, Tripled votes, Missing memory cards, Machine malfunctions, Software glitches, Undervotes, Overvotes. Reports of voting machine failures flooded the news after the last elections and left most voters wondering "Does my vote really count?" "Can these electronic voting machines be trusted?" "How secure are my state's voting systems?" In December 2007, we published an in depth, source code and h....
|
|
Schuyler Towne & Jon King: How to make Friends & Influence Lock Manufacturers
-
www.defcon.org
-
19 years ago
-
eng
Locksport is growing up in America. In this talk we will explore four case studies demonstrating how the community has leveraged itself to bring about significant advances in the lock industry. We will demonstrate exploits discovered in both Medeco and ABUS high security locks and discuss how Kwikset's Smartkey system responded to the spread of information about bumping and how they plan to work with the community in the future. We will inv....
|
|
Scott Moulton: Solid Stated Drives Destroy Forensic & Data Recovery Jobs: Animated!
-
www.defcon.org
-
19 years ago
-
eng
This speech is all ANIMATION in 3D! Data on a Solid State Device is virtualized and the Physical Sector that you are asking for is not actually the sector it was 5 minutes ago. The data moves around using wear leveling schemes controlled by the drive using propriety methods. When you ask for Sector 125, its physical address block is converted to an LBA block and every 5 write cycles the data is moved to a new and empty previously erased blo....
|
|
In 2007 SensePost demonstrated the how DNS and Timing attacks could be used for a variety of attacks. This year we take those attacks further and show how small footholds in a target network can be converted into portals we can (and do) drive trucks through! With some updated SensePost tools, and some brand new ones, we will demonstrate how to convert your simple SQL Injection attacks (against well hardened environments) into point and clic....
|
|
Signaure-based Antivirus is dead, we want to show you just how dead it is. This presentation will detail our findings from running the Race-2-Zero contest during DC16. The contest involves teams or individuals being given a sample set of malicious programs to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat. The first to ....
|
|
Taylor Banks & Carric: Pen-Testing is Dead, Long Live the Pen Test
-
www.defcon.org
-
19 years ago
-
eng
This talk explores the death and subsequent re-birth of the penetration test. Comprised of conclusions drawn from the collective experiences of two seasoned pen-testers, our talk is filled with facts, fun and rhetoric. We will describe the landscape, the problems, and offer real solutions. In our talk, we will explore the problems with modern-day pen-tests and pen-testers, and ways to stand out amongst the frauds selling their lacklust....
|
|
Thomas d'Otreppe de Bouvette aka Mister_X & Rick Farina:Shifting the Focus of WiFi Security: Beyond cracking your neighbor's wep key
-
www.defcon.org
-
19 years ago
-
eng
In this talk we will discuss the paradigm shift of WiFi attacks away from the Access Points and focusing toward the clients. We will cover in depth how simple tricks such as HoneyPot Access Points or even hotspotter simply are not enough anymore and more flexible and powerful methods are being developed and used. The older, dated technologies built into Access Points for ensuring network security have failed the test of time paving way for ....
|
|
There has been a recent global push for the creation of Hacker Spaces. Unfortunately, these ventures are risky and can be quite costly. In an effort to provide an alternative, or at least an intermediary step, this talk will discuss a different type of Hacker Space, one that is on wheels. During the course of this speech, we will discuss the advantages and disadvantages of building a mobile hacker space, and present a real-world example, wh....
|
|
Tom Stracener & Robert Hansen: Xploiting Google Gadgets: Gmalware and Beyond
-
www.defcon.org
-
19 years ago
-
eng
Google Gadgets are symptomatic of the Way 2.0 Way of things: from lame gadgets that rotate through pictures of puppies to calendars, and inline email on your iGoogle homepage. This talk will analyze the security history of Google Gadgets and demonstrate ways to exploit Gadgets for nefarious purposes. We will also show ways to create Gadgets that allow you to port scan internal systems and do various JavaScript hacks via malicious (or useful....
|
|
Tony Howlett: The Death of Cash: The loss of anonymity and other dangers of the cash free society
-
www.defcon.org
-
19 years ago
-
eng
In this talk, we will discuss the pros and cons (mostly cons) of the cash less society and how it might endanger your privacy and civil liberties. This movement towards the elimination of cash has been picking up speed and mostly accepted by the populace as a huge convenience. We examine some reasons why this isn't such a good thing. We also look at legislation and laws in this area that give banks and the government unprecedented ability t....
|
|
Tottenkoph,Rev & Philosopher: Hijacking the Outdoor Digital Billboard Network
-
www.defcon.org
-
19 years ago
-
eng
Outdoor digital billboards are becoming the new way to advertise multiple products/services/etc with a single board as compared to having a street littered with dozens of these eyesores. Therefore, they're more fun to take apart and play with. While driving one day, I noticed a 404 error on one of these billboards and after discussing it with my fellow speakers, hatched a plan to hack into their network and advertise our own ideas/ "product....
|
|
In 1990, a wire-bound book was published in Paris by the title of &qoutVoyage au centre de la HP28 c/s&qout". It presents a very thorough account of the inner workings of the Hewlett Packard 28 series of graphing calculators. Designed before the days of prepackaged microprocessors, the series uses the Saturn architecture, which HP designed in-house. This architecture is very different from today's homogeneous RISC chips, with registers of 1....
|
|
When penetration testing large environments, testers require the ability to maintain persistent access to systems they have exploited, leverage trusts to access other systems, and increase their foothold into the target. Post exploitation activities are some of the most labor intensive aspects of pen testing. These include password management, persistent host access, privileged escalation, trust relationships, acquiring GUI access, etc. Pen....
|
|
Vic Vandal: Keeping Secret Secrets Secret and Sharing Secret Secrets Secretly
-
www.defcon.org
-
19 years ago
-
eng
Have you ever wanted to: Transmit secret codes and messages Protect Nuclear launch codes Dabble in Intellectual Property protection Warez/file-sharing with legal liability protection Develop and share terrorist plots Smuggle illegal substances Hide digital pr0n from others Exchange classified information securely Exchange diskette with "Leonardo da Vinci" virus, culled from the hacked "garbage" file on the Gibs....
|
|
Compliance is no longer new. Compliance has been accepted by the corporate-state. Compliance is common-place. Compliance is the intruders' new friend. Decision makers thinks Compliance == Security. While many compliance standards have resulted in the implementation of some very important controls, they have also left a roadmap for intruders, ill doers and the sort to hone their attack. This presentation will go over such weaknesses and show..
|
|
Wendel Guglielmetti Henrique: Playing with Web Application Firewalls
-
www.defcon.org
-
19 years ago
-
eng
WAF (Web Application Firewalls) are often called 'Deep Packet Inspection Firewalls' because they look at every request and response within the HTTP/HTTPS/SOAP/XML-RPC/Web Service layers. Some WAFs look for certain 'attack signatures' to try to identify a specific attack that an intruder may be sending, while others look for abnormal behavior that doesn't fit the websites normal traffic patterns. Web Application Firewalls can be either softw....
|
|
Need help understanding your gigabytes of application logs or network captures? Your OS performance metrics do not make sense? Then DAVIX, the live CD for visualizing IT data, is your answer! To simplify the analysis of vast amounts of security data, visualization is slowly penetrating the security community. There are many free tools available for analysis and visualization of data. To simplify the use of these tools, the open source ....
|
|
Zac Franken: Is that a unique credential in your pocket or are you just happy to see me?
-
www.defcon.org
-
19 years ago
-
eng
This year new shiny toys are abound, as I'll tell you about the credentials in your wallet, and even in you. How secure (or not) they are and a few ways to duplicate / replicate /emulate them. Last year at Defcon 15 I had a bit of a chat with you guys and gave you an overview of access control systems, told you of their common flaw, and showed you some cool toys that exploit it. This year, from the humble magnetic stripe card to the mo....
|
|
Today’s trip was like taken directly out of the lonely planet guidebook. Our guide Said Azawi (todo: double check last name) picked us up at the hotel at the appointed time. Driving over Gezira, past the Cairo Opera house and into Giza we arrived at the pyramids at the Giza Plateau early. We were a bit suspicious about the whole deal, but the guide recommended we get horses or camels to take us across the plateau.
|
|
The “kobyuutr” on which I am writing this has an arab/english keyboard, so I will write in english) We arrived late at night at Cairo international airport, and got a first impression of Egyptian bureaucracy that has remained. We ended up standing in lines for a long time, and when we finally were through, it was 2 am, and we did not feel like dealing with Cairo’s infamous taxis. So we took a “limosin service” to the hotel.
|
|
I am happy to see others express positive opinions about universal DAO interfaces in Java. Per Mellqvist writes in developerWorks: “Don’t Repeat the DAO” about creating a GenericDao interface: public interface GenericDao
|
|
Due to popular demand, I will post a very short version of my Lazy Loading article: Why? Because this is bad: Category category = dao.get(1); Category parent = dao.get(category.parentId); int sumChildValue = 0; for (Long childId : parent.subcategoryIds) { sumChildValue += dao.get(childId).getValue(); } System.out.println(sumChildValue); This is good: Category category = dao.get(1); int sumChildValue = 0; for (Category sibling : category.get..
|
|
Status: This article is currently pretty dry. I’d like feedback on how to make it more eloquent. In my previous blog post, I promised to write more about using databases as the main integration strategy. In the current post, I plan to cover maybe the most important question: “Why?” Imagine an application where every time it wants to communicate with another system, it reads or writes to the database. For now, let’s ignore how this would wor..
|
|
The Intermedium of Tissue A variable represents a set of words in a particular order. For example, x might equal the word-set {the quick brown fox jumped over the lazy dog}. Note that the bracket represents the boundary of the word-set and is not included in the set itself. A piece of writing, whether it […]
|
|
Before Web Services, there was CORBA. Before CORBA, there was DCOM. Before DCOM, there was RPC. Before RPC, there was BSD sockets. Before sockets, there were databases. And as it was in the beginning, so shall it too be in the end. The only systematically successful strategy in the history of computing is databases. I have discovered more and more lately that integration using a database is well-defined (DDLs - a WSDL that works!
|
|
I really wish you’d stop using that word - I don’t think it means what you think it means.” (The Princess Bride - of course) When my wife asked “are you a feminist,” I realized I don’t like words very much. To some people, “feminism” means women who dress like men, think pornography is destroying society and that all men are inherently evil. You know the type I’m talking about. To many others, including my wife, a “feminism” is “the radical..
|
|
Here are some of my favorite words. Signs of danger ‘Just’: bad word, as in “can’t we just develop the greatest application ever”, “can’t we just replace the database with JavaSpaces”, “can’t we just expose the functionality to the world as a web service”. ‘Should’: bad word, as in “it _should_n’t take more than a few days to do that, should it,” “integrating two systems should be easy.” Listen for use of this word from people who … should ..
|
|
I’ve again gotten quite backlogged with publishing photos from various adventures. Today I fortunately had time to push tree sets on Flickr : Midgard developer meeting in Komorniki, Poland GUADEC 2006 in Vilanova i Geltru, Catalonia Death Monkey 2006 rally from Helsinki to Gibraltar Enjoy!
|
|
I’ve again gotten quite backlogged with publishing photos from various adventures. Today I fortunately had time to push tree sets on Flickr : Midgard developer meeting in Komorniki, Poland GUADEC 2006 in Vilanova i Geltru, Catalonia Death Monkey 2006 rally from Helsinki to Gibraltar Enjoy!
|
|
Update: Rewrote several sections “Fools ignore complexity; pragmatists suffer it; experts avoid it; geniuses remove it.” - Alan Perlis This article contains some things I have learned that has made me into a better developer than I was before I learned them. There are nine tips. These are not necessarily the only, or the best things I have learned, but I like the number nine. Becoming a better developer is a complex path.
|
|
Updated for republication in Mr Bool In my experience, the most serious bugs in programs in production are in error handling routines. Inventive programmers often try fancy things when dealing with errors, but error situations are often omitted during testing. This article examines the fundamental questions of exceptions: What causes exceptions, and what can be done with them? Bad User, Bad Server, or Bad Programmer Practices of an Agile De..
|
|
What happens when a customer asks for a simple new bit of functionality? Do you have to execute changes on four different systems, test each in isolation and in combination, involve a separate testing, infrastructure and operations team? If so, your architecture is probably not service oriented. In this post, I will examine the real meaning of coupling, and how it relates to SOA. I will, like others taking about SOA, try to define what I me..
|
|
After I switched from Movable Type to Wordpress as my blogging software, the comment spam problem has returned from the grave. So I’ve looked for good solutions for WordPress: I ended on a verbal CAPTCHA with a math question (which may also keep stupid commenters out - not that I have any of those, of course). I am considering some of the “fight-back” solutions out there too: Maybe returning a really big response really slowly when spam is ..
|
|
What is the next letter in this sequence: A E I. And this sequence: A B G D? How about this one: B C D G J? A boy and his mother are in a horrible car accident. They are rushed to the hospital, but on the way, the mother dies. When they arrive at the hospital, the nurse exclaims: “But that is my son!”. How can that be? You’re in the basement of a house.
|
|
My article series on Lazy Loading will be published on java.net tomorrow. In relationship to the publication, I am taking down the original articles from my blog. Please go to Java.net for to read about lazy loading. Update: The article was just posted last Tuesday. I have updated the links in this post.
|
|
Myopia: the inability to see distant objects as clearly as near objects. PreferredConsumer.com What makes a good statement? In my experience, a good statement is one that people will disagree with frequently. One of the internal quality auditors at my company has an excellent plaque in her office: “If you and I agreed all the time, one of us would be superfluous”. So, in the spirit of disharmony: Agile development is all about being myopic,..
|
|
We just got back from vacation this week! No computers, no telephones, no IM, no text messages, no stress (just the occasional deer, moose or bear). Several years ago, I didn’t take any vacation at all during the year and promptly vowed never to do that again. In just one week of vacation, you can reduce all of the stress that you worked so hard to build up all year long. Remember that Canadian companies are famous worldwide for overworki..
|
|
We just got back from vacation this week! No computers, no telephones, no IM, no text messages, no stress (just the occasional deer, moose or bear). Several years ago, I didn’t take any vacation at all during the year and promptly vowed never to do that again. In just one week of vacation, you can reduce all of the stress that you worked so hard to build up all year long. Remember that Canadian companies are famous worldwide for overworki..
|