|
The Dark Tangent acknowledges those who made Defcon 12 possible, contest winners and the techniques that were used to win.
|
|
Cameron nummish Hotchkies,Blind SQL Injection Automation Techniques
-
www.defcon.org
-
20 years ago
-
eng
Due to improper software design and implementation practices, the number of web-based applications vulnerable to SQL injection is still alarmingly high. Yet the actual steps used to exploit these applications remain very tedious and repetitive. This presentation will focus on methods available to automate the task of exploiting blind sql injection holes. It will also feature a new tool, 'sQueaL" and explain some of the research, used in the....
|
|
Robert "hackajar" Imhoff-Dousharm and Jonathan "ripshy" Duncan, Credit Card Networks Revisted: Penitration in Real-Time
-
www.defcon.org
-
20 years ago
-
eng
Credit card authorization is the core to all major businesses, both on and off the Internet. Yet an alarming number of businesses are not taking the right steps to insure that your credit cards are secure against fraud and theft. In bringing this to light (Credit Card Networks 101, July 31 2003 - DC 11), you were awed at the posibility, but were not provided with any real proof. This year we, that's you and I, will walk through the process ....
|
|
Ian Vitek, Exploring Terminal Services, The Last 12 Month of Research. Or, The Evil Admin And His Tools
-
www.defcon.org
-
20 years ago
-
eng
got shell? On a Citrix or Terminal Services server? The speech will demonstrate some common ways to explore Terminal Services. Uploading files with the keyboard and elevate luser rights to SYSTEM. How secure is it for a client to connect to a Citrix or a Terminal Services server if an evil admin owns the box? Tools and exploits will be released. Ian Vitek: 183 cm. 80 Kg. Brown eyes. Brown hair. Eats meat. Drinks almost..
|
|
In September of 2003, a noted security consultant was terminated from his job over controversy surrounding a document that he co-authored. One key focus of the document was the risk associated with operating system monocultures. This idea was nothing new. In fact, in 1989, the following passages appeared in a book that spent over four months on the New York Times best seller list: "Just like genetic diversity, which prevents an epidemi....
|
|
Information Hiding techniques are much researched in the context of watermarking or fingerprinting images and sound files, mainly as a means of copyright protection and piracy prevention/detection. Those mediums offer a significant amount of redundancy, thus lending themselves to the implementation of robust IH systems. Executables however do not offer such amounts of redundancy, and have thus far proven to be a difficult and rarely used me....
|
|
Michael Davis, The Open-Source Security Myth and How to Make It A Reality
-
www.defcon.org
-
20 years ago
-
eng
Open Source software is frequently described as more secure, than closed source software for two reasons: the number of people available to correct a problem is potentially larger; and anyone can review the source code for vulnerabilities or malicious code. Unfortunately, the current state of design documentation does not support a cost-effective security review. In addition to compromising the confidence in the software, the lack of ....
|
|
The insecure workstation. A creative look at the windows group policies as a security solution in today's workplace and how easily they are circumvented. This talk will discuss the Were, What and Why on policies and also demonstrate simple tricks to bypass policies and exploiting poor policy implementation. Deral Heiland has been in the IT field since 1994 working in the following industries; Newspaper media, System Integrator, Manufac..
|
|
Maximillian Dornseif, Far More Than You Ever Wanted To Tell - Hidden Data In Document Formats
-
www.defcon.org
-
20 years ago
-
eng
Applications usually put all kinds of information besides the ones which you intend to into saved documents. This can lead to embarrassing revelations. We will take a look into different types of application data and what can be hidden in there. This allows us to 'scrub" our own documents to avoid unwanted information in there but also to look for information in documents which the authors didn"t want to hand out. Go grasp the scope of the ....
|
|
For close to 100 years amateurs have been working with radios and sending transmission all over the world. The dawn of the information age has inspired many new technologies and advancements in communication; and amateur radio is no exception. Today's modern amateur radio operators are building wireless networks and enjoying several advantages over their unlicensed counterparts. This presentation will review some of these advantages as well....
|
|
Google hacking is not new, but it's back and deadlier than ever. This talk is the follow-up to last years very successful talk "Watching the Watchers". Attendees will learn the tricks and tactics that any self-respecting Google hacker should know. Expanded extensively since last year, the techniques and always killer examples from the "googledorks" database are always a crowd-pleaser. Witness how sites from all over the net fall victim to s....
|
|
Michael T. Raggo , Steganography, Steganalysis and Cryptanalysis
-
www.defcon.org
-
20 years ago
-
eng
This presentation will present Steganography and techniques for Steganalysis (identifying files with hidden messages). A review of Steganography will provide the basis for identifying and dissecting carrier files. There will also be a demonstration of carrier file analysis and disection. There will also be a demo of my new Steganography detection program, StegSpy. Cracking and reverse-engineering Steganography programs will also be covered.....
|
|
Wavyhill and Andre Goldman,Toward a Private Digital Economy (Trusted Transactions In An Anonymous World)
-
www.defcon.org
-
20 years ago
-
eng
Current financial privacy tools have drawbacks arising from centralized ownership and control, and the limitations of the service-for-profit model. A better approach is to construct a fully distributed environment for economic activity which mimics in freedom and variety of action the way cash is used in the physical world.The key to this variety is the element of locale. We introduce the "Farmer's Market" model of anonymous commerce a....
|
|
On even a moderately sized network, activity can easily reach the order of millions, perhaps billions, of packets. Hidden in this sea of data is malicious activity. Current network analysis and monitoring tools primarily use text and simple charting to present information. These methods, while effective in some circumstances, can overwhelm the analyst with too much, or the wrong type of, information. This situation is worsened by today's al....
|
|
Phreaking in the age of Voice Over IP? What the hell is Voice Over IP? If you're asking this question and you'reinterested in phones and thought phreaking was dead back in the early "80s when blueboxing died, or 2002 when ATandT killed redboxing on long distance calls then this is the speech for you. Or if you know what VoIP is but want to know how the hell it has any impact on phreaking you should also attend. This talk intends to ed....
|
|
Despite decades of evolution, Internet file transfer is still plagued with problems to which formalized solutions are either inadequate or nonexistent. Lack of server-side bandwidth often renders high demand content inaccessible (which we affectionately refer to as the Slashdot effect). When the ability of a single server to provide content is exceeded, manual mirror selection is often utilized, providing an unnecessary and often problemati....
|
|
Wendy Seltzer and Seth Schoen, Hacking the Spectrum: Open Source Software vs. the Broadcast Flag
-
www.defcon.org
-
20 years ago
-
eng
The FCC, at Hollywood's request, has mandated a broadcast flag for high-definition digital television (HDTV). By July 2005, it will be unlawful to sell devices that don"t respond to a "do not copy" flag or that provide unencumbered high-definition digital outputs. The flag's "robustness" requirement will make it impossible to build an open-source HDTV version of the TiVo. This talk will demonstrate how these rules thwart user innovation, sh....
|
|
Continuing the research done in previous years on advanced protocol manipulation and the high speed evaluation of large network characteristics, this year's Black Ops of TCP/IP goes into new territory with a deep analysis of the Domain Name System. A core element of the TCP/IP application suite, it is everywhere and there is unexpected power contained within. * Interesting Facets of the Global DNS Architecture: A high speed scanner for....
|
|
Nathan Hamiel (Ichabod Ver7),Down with the RIAA, Musicians against the Recording Industry
-
www.defcon.org
-
20 years ago
-
eng
Down with the RIAA is a look at the current state of the music business and where it is headed. The presentation uses statistics and facts to map out where the industry currently is and details the problems with the current model. After the problems with the current model are shown then the groundwork for the future of the music business is laid out showing how the recording industry is no longer needed. Included in the presentation is info....
|
|
The goal of Prometheus is to create an Open Source project that takes into account the inherent flaws in the Microsoft implementation of Alternate Data Streams (ADS) and uses those attributes to create a tool for increased security. The concept is similar to making lemonade from lemons. We"re taking an insecure component of the NTFS file system and creating a tool that will provide increased security. Russ and Grifter will be explaining and....
|
|
It seems that the major target of most online bugs is actually quite the same. Over and over again the uninspired, pop the box, seems to be what most writers are after. In this talk I will explore a bit of virus history in relation to goals, starting with older viral intentions, moving to what appears to be the intentions today and what possibly could be the intentions tomorrow. This talk will be fairly abstract and I will setup t....
|
|
Michael Rash, Advanced Netfilter; Content Replacement (ala Snort_inline), and Port Knocking Based on Passive OS Fingerprinting
-
www.defcon.org
-
20 years ago
-
eng
The boundaries between network access control devices and network monitoring devices are steadily becomming blured. Network intrusion detection systems are moving into the realm of not only monitoring network traffic, but also modifying it either through dynamic reconfiguration of firewall rulesets, spoofed session-busting traffic, or outright alteration of application layer data (ala Snort_inline). Firewalls themselves are also getting sma....
|
|
Panel, Ask EFF: Discussion and Q/A on the State of Digital Liberties
-
www.defcon.org
-
20 years ago
-
eng
The Electronic Frontier Foundation (EFF) is one of the premiere digital liberties organizations in the world. We fight for freedom of expression on the Internet, the right for researchers and consumers to reverse-engineer their devices, expansion of the public domain, and electronic privacy and anonymity. On this panel, three representatives of EFF will discuss the latest developments in digital liberties, including free speech on the Inter....
|
|
CrimethInc, Electronic Civil Disobedience and the Republican National Convention
-
www.defcon.org
-
20 years ago
-
eng
Electronic Civil Disobedience and the Republican National Convention An introduction to the theory of hacktivism and the usage of hacking skills as a means of fighting for social justice by pressuring corporations and government to adopt progressive changes. Explores the history of electronic civil disobedience, tips on how to wage your own ECD campaigns, and how to participate in the upcoming actions to coincide with the protests agai....
|
|
The IPv6 Primer will encompass the basics of IPv6, including some of its roots, the transitioning mechanisms available, and some security concerns early adopters should be aware of in several different environments. This presentation is meant for anyone who has heard about IPv6, but would like to know the basics of the protocol and its implementation. Gene Cronk, CISSP, NSA-IAM, resides in Jacksonville, FL and is currently providing sy....
|
|
Elonka Dunin,Kryptos and the Cracking of the Cyrillic Projector Cipher
-
www.defcon.org
-
20 years ago
-
eng
In a courtyard at CIA Headquarters stands an encrypted sculpture called Kryptos. Its thousands of characters contain encoded messages, three of which have been solved. The fourth part, 97 or 98 characters at the very bottom, have withstood cryptanalysis for over a decade. The artist who created Kryptos, James Sanborn, has also created other encrypted sculptures such as the decade-old Cyrillic Projector, which was cracked last September by a....
|
|
The search for a unified theory of everything in contemporary physics stems in part from the fundamental inability to reconcile quantum physics and relativity theory. This has pushed research toward complex mathematical models such as string theory in an effort to model a single way of looking at everything. The same can be said of the distribution of power in networks and hierarchies. The individual person looks like one kind of thing....
|
|
Do you think using Internet Telephony is more secure than a regular phone? Think again! Internet Telephony is becoming more common and those that think it is safer from wiretaps than regular phone communications are wrong. This presentation will demonstrate how to decrypt Net2Phone's dialed phone numbers, and playback fully reconstructed audio conversations from network packet captures. Included will be a demonstration of NetWitness 5.0's V....
|
|
Privacy doesnt mean the same thing to everyone... Since you"re interacting in a global space, you need to understand what people outside your immediate frame of reference are thinking when they talk about privacy because what they think will influence ttheir expectations and their actions. This talk will give you the opportunity to examine some other views of privacy, explore your own thinking, and compare it with others both from the globa..
|
|
Sun Tzu once stated, "Know your enemy and know yourself, and in a hundred battles you will never be defeated." By denying outsiders information about our systems and software, we make it more difficult to mount successful attacks. There are a wealth of options for OS-fingerprinting today, evolving from basic TCP-flag mangling tools such as Queso, through the ICMP quirk-detection of the original Xprobe, and the packet timing analysis of....
|
|
Kevin Mahaffey, Smile, You"re on Candid Camera: The Changing Notions of Surveillance in Postmodern America
-
www.defcon.org
-
20 years ago
-
eng
Recently, surveillance has become somewhat of a pop-culture fascination. From the Reality TV shows permeating every network's line up to the webcam phenomenon of the late 1990s, surveillance has become more a source of entertainment than ever before. Benjamin Franklin's quote, Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety, has long served to exemplify the American, Big B....
|
|
Jesee Krembs and Nicholas Farr, The Hacker Foundation: An Introduction
-
www.defcon.org
-
20 years ago
-
eng
The Hacker Foundation (THF) is a non-profit organization dedicated to establishing and maintaining a research and service organization to promote and explore the creative use of technological resources. Simply put, we want to help people do useful things with technology. This announcement is a formal launch of the foundation. There will be a brief statement about the foundation's goals, operations and how the foundation can work for you. ..
|
|
Brett Moore, Shoot the Messenger Using Window Messages to Exploit Local win32 Applications
-
www.defcon.org
-
20 years ago
-
eng
The windows GDI interface uses messages to pass input and events to windows. As there is currently no way of determining who the sender of the message is, it is possible for a low privileged application to send messages to and interact with a process of higher privilege. This presentation will cover in details some of the flaws exposed through these messages, and demonstrate how they can be exploited to conduct privilege escalation and..
|
|
Jason Scott of TEXTFILES.COM, a site dedicated to the history of Dial-Up Bulletin Board Systems, embarked on a quest to film an all-inclusive BBS documentary in 2001. What started out as a one-year project grew to three, and what started as a two-hour film will be a six-hour series. Thousands of miles of travel and 200 interviews later, the production is now nearing the end of editing and the release date. Jason tells you what he learned, w....
|
|
Since the introduction of metamorphic stealth in the computer virus world, it has been suggested that the method can also be used to protect any, even legitimate, code. The only downfall of this technique is that how the engine manipulates the code remains constant. This allows the original code to be obtained by using an optimizer. The next step for this stealth method is to create an engine that will change how the code in manipulated. Th..
|
|
When the Tables Turn Until now network security defences have largely been about building walls and fences around the network. This talk revolves around spiking those walls and electrifying those fences! During this talk we will highlight techniques (and tools) that can be used to turn the tables on prospective attackers with passive-Strike-Back. We will explore the possibilities across the assesment spectrum responding to the standard....
|
|
Hearken back to the days of yesterday, circa 1993, when men were men, the Internet "backbone" was T3 and run by ANS, and a few brave start-up companies around Washington D.C. were fighting the phone company and each other to build the "commercial" Internet. One of them, DIGEX, literally started out in the founder's basement in "92 and rapidly grew to be a major force in what ultimately became known as web hosting. DIGEX "invented" web hosti....
|
|
Automotive Networks This presentation provides an introduction to the electronic networks present on late model automobiles. These networks will be described loosely following the OSI model of networking. Common uses of these networks will be presented, and the privacy implications of some uses will be questioned. The presentation will conclude with an introduction to OpenOtto, a free software and hardware project implementing the netw..
|
|
NoSEBrEaK Defeating Honeynets Honeynets are one of the more recent toys in the white-hat arsenal. They are usually assumed to be hard to detect and attempts to detect or disable them can be unconditionally monitored. Sometimes it is even suggested that deploying honenets is a way to incerase security. We scrutinize this assumption and demonstrate a method how a host in a honeynet can be completely controlled by an attacker without any ....
|
|
Smart Cards are used all over the place in every day life. The unfortunate (or fortunate) side of Smart Cards is that most widely deployed systems don"t use any real security and rely mostly on obscurity. This presentation will discuss the different types of Smart Cards, exactly how to reverse engineer the protocols they use, and how to exploit their security weaknesses. For demonstration, we will look at GSM SIM Cards and San Diego Parking....
|
|
The Metasploit Framework has progressed from a simple network game to a powerful tool for administrators and security analysts alike. Over the past several months, the Framework has been enhanced with improved exploit techniques and a truly advanced suite of payloads. This presentation provides a background on what exploit frameworks are, what they can provide you, and why you should be using one. A live demonstration will highlight many of....
|
|
Adam Bresson, Identification Evasion: Knowledge and Countermeasures
-
www.defcon.org
-
20 years ago
-
eng
Everyday you"re right to privacy is being compromised! From security cameras, to illegal searches, to unauthorized monitoring you are being watched. You must protect yourself...and your rights. Using Identification Evasion, you can immediately strengthen your protections. I"ll discuss knowledge and countermeasures in the Computer and Real Worlds while presenting many great methods to turn the tables on surveillance. In addition to other in-....
|
|
VICE - Catch the Hookers! Rootkits are the backbone of software penetrations. They provide stealth and consistent access to a computer system. Rootkits employ technology for covert ex-filtration of data, IDS evasion, and anti-forensics. Rootkit technology is now incorporated into the most deadly of threats, network worms. Serious security professionals must understand rootkit technology in detail. Commercial anti-virus technology is wo....
|
|
Nick Mathewson,Snake Oil Anonymity: How To Spot It, And How Not To Write It
-
www.defcon.org
-
20 years ago
-
eng
Much software that promises "anonymity" fails to deliver, as witnessed by a succession of compromised file-trading networks, back-doored communications systems, overhyped vapornets, and insecure "improvements" on existing remailer networks. I"ll discuss a bunch of allegedly anonymous systems, and explain how a clever attacker can defeat each of them. Audience members will learn to recognize the warning signs of broken anonymity in anonymous..
|