|
Sean Malone - HiveMind: Distributed File Storage Using JavaScript Botnets
-
media.defcon.org
-
13 years ago
-
eng
HiveMind: Distributed File Storage Using JavaScript Botnets SEAN MALONE PRINCIPAL SECURITY CONSULTANT, FUSIONX Some data is too sensitive or volatile to store on systems you own. What if we could store it somewhere else without compromising the security or availability of the data, while leveraging intended functionality to do so? This presentation will cover the methodology and tools required to create a distributed file store built on....
|
|
Sean Malone - HiveMind: Distributed File Storage Using JavaScript Botnets
-
media.defcon.org
-
13 years ago
-
eng
HiveMind: Distributed File Storage Using JavaScript Botnets SEAN MALONE PRINCIPAL SECURITY CONSULTANT, FUSIONX Some data is too sensitive or volatile to store on systems you own. What if we could store it somewhere else without compromising the security or availability of the data, while leveraging intended functionality to do so? This presentation will cover the methodology and tools required to create a distributed file store built on....
|
|
Adam Laurie and Zac Franken - Decapping Chips the Easy Hard Way
-
media.defcon.org
-
13 years ago
-
eng
Decapping Chips the Easy Hard Way ADAM "MAJOR MALFUNCTION" LAURIE CODE MONKEY, APERTURE LABS ZAC FRANKEN CHIP MONKEY, APERTURE LABS For some time it has been possible to discover the inner workings of microprocessors with the help of a microscope and some nasty chemicals such as fuming nitric acid. However, unless you have access to a university or work science lab, this is beyond the reach of most hackers, and, even it were to be att....
|
|
Adam Laurie and Zac Franken - Decapping Chips the Easy Hard Way
-
media.defcon.org
-
13 years ago
-
eng
Decapping Chips the Easy Hard Way ADAM "MAJOR MALFUNCTION" LAURIE CODE MONKEY, APERTURE LABS ZAC FRANKEN CHIP MONKEY, APERTURE LABS For some time it has been possible to discover the inner workings of microprocessors with the help of a microscope and some nasty chemicals such as fuming nitric acid. However, unless you have access to a university or work science lab, this is beyond the reach of most hackers, and, even it were to be att....
|
|
David Kennedy and Nick Hitchcock - The Dirty South – Getting Justified with Technology
-
media.defcon.org
-
13 years ago
-
eng
The Dirty South – Getting Justified with Technology DAVID KENNEDY FOUNDER & PRINCIPAL SECURITY CONSULTANT, TRUSTEDSEC NICK HITCHCOCK SENIOR SECURITY CONSULTANT, TRUSTEDSEC It seems that every day there's a new NextGen firewall, whitelisting and blacklisting, DLP, or the latest technology thats suppose to stop us. But does it really stop "hackers"? Truth is, naw not really. In this talk we'll be showing off the latest bypass techniq....
|
|
David Kennedy and Nick Hitchcock - The Dirty South – Getting Justified with Technology
-
media.defcon.org
-
13 years ago
-
eng
The Dirty South – Getting Justified with Technology DAVID KENNEDY FOUNDER & PRINCIPAL SECURITY CONSULTANT, TRUSTEDSEC NICK HITCHCOCK SENIOR SECURITY CONSULTANT, TRUSTEDSEC It seems that every day there's a new NextGen firewall, whitelisting and blacklisting, DLP, or the latest technology thats suppose to stop us. But does it really stop "hackers"? Truth is, naw not really. In this talk we'll be showing off the latest bypass techniq....
|
|
Daniel Burroughs - Open Public Sensors, Trend Monitoring and Data Fusion
-
media.defcon.org
-
13 years ago
-
eng
Open Public Sensors, Trend Monitoring and Data Fusion DANIEL BURROUGHS ASSOCIATE DIRECTOR OF TECHNOLOGY, CENTER FOR LAW ENFORCEMENT TECHNOLOGY, TRAINING AND RESEARCH Our world is instrumented with countless sensors. While many are outside of our direct control, there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fas....
|
|
Daniel Burroughs - Open Public Sensors, Trend Monitoring and Data Fusion
-
media.defcon.org
-
13 years ago
-
eng
Open Public Sensors, Trend Monitoring and Data Fusion DANIEL BURROUGHS ASSOCIATE DIRECTOR OF TECHNOLOGY, CENTER FOR LAW ENFORCEMENT TECHNOLOGY, TRAINING AND RESEARCH Our world is instrumented with countless sensors. While many are outside of our direct control, there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fas....
|
|
Doug DePerry and Tom Ritter - I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell
-
www.defcon.org
-
13 years ago
-
eng
I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell DOUG DEPERRY SENIOR SECURITY CONSULTANT, ISEC PARTNERS TOM RITTER SENIOR SECURITY CONSULTANT, ISEC PARTNERS I have a box on my desk that your CDMA cell phone will automatically connect to while you send and receive phone calls, text messages, emails, and browse the Internet. I own this box. I watch all the traffic that crosses it....
|
|
Doug DePerry and Tom Ritter - I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell
-
media.defcon.org
-
13 years ago
-
eng
I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell DOUG DEPERRY SENIOR SECURITY CONSULTANT, ISEC PARTNERS TOM RITTER SENIOR SECURITY CONSULTANT, ISEC PARTNERS I have a box on my desk that your CDMA cell phone will automatically connect to while you send and receive phone calls, text messages, emails, and browse the Internet. I own this box. I watch all the traffic that crosses it....
|
|
In part 1 of this series I discussed traditional reasons people have for buying software, which turned out mostly to be based on perceived or real issues with building software. I discuss in this post, which contains parts 2 and 3, issues with buying software. Part 2: Traditional issues with buying
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
DEF CON 21 Printed Program in PDF Just in case you need a digital copy of the program, maybe you lost yours from the show or it's dog eared, here's a fresh copy for you. https://www.defcon.org/images/defcon-21/dc-21-program.pdf
|
Meet the VCs PING LI PARTNER, ACCEL PARTNERS MATT OCKO PARTNER, DATA COLLECTIVE DEEPAK JEEVANKUMAR PARTNER, GENERAL CATALYST JOHN M. JACK BOARD PARTNER, ANDREESSEN HOROWITZ EILEEN BURBIDGE PARTNER, PASSION CAPITAL Venture capital investments have reached the highest level since the dot-com days. Almost seven billion dollars was invested last quarter alone. While clean-tech deals hit a new low, security deals increased the most. ....
|
Meet the VCs PING LI PARTNER, ACCEL PARTNERS MATT OCKO PARTNER, DATA COLLECTIVE DEEPAK JEEVANKUMAR PARTNER, GENERAL CATALYST JOHN M. JACK BOARD PARTNER, ANDREESSEN HOROWITZ EILEEN BURBIDGE PARTNER, PASSION CAPITAL Venture capital investments have reached the highest level since the dot-com days. Almost seven billion dollars was invested last quarter alone. While clean-tech deals hit a new low, security deals increased the most. ....
|
Ask the EFF: The Year in Digital Civil Liberties KURT OPSAHL ELECTRONIC FRONTIER FOUNDATION MARCIA HOFFMANN FELLOW, EFF DAN AUERBACH STAFF TECHNOLOGIST, EFF EVA GALPERIN GLOBAL POLICY ANALYST, EFF MARC JAYCOX POLICY ANALYST AND LEGISLATIVE ASSISTANT, EFF MITCH STOLTZ STAFF ATTORNEY, EFF Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundati....
|
Ask the EFF: The Year in Digital Civil Liberties KURT OPSAHL ELECTRONIC FRONTIER FOUNDATION MARCIA HOFFMANN FELLOW, EFF DAN AUERBACH STAFF TECHNOLOGIST, EFF EVA GALPERIN GLOBAL POLICY ANALYST, EFF MARC JAYCOX POLICY ANALYST AND LEGISLATIVE ASSISTANT, EFF MITCH STOLTZ STAFF ATTORNEY, EFF Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundati....
|
The ACLU Presents: NSA Surveillance and More ALEX ABDO STAFF ATTORNEY, ACLU NATIONAL SECURITY PROJECT CATHERINE CRUMP STAFF ATTORNEY, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT KADE CROCKFORD ACLU OF MASSACHUSETTS TECHNOLOGY FOR LIBERTY PROJECT NICOLE OZER TECHNOLOGY AND CIVIL LIBERTIES POLICY DIRECTOR, ACLU OF CALIFORNIA From the NSA's PRISM and....
|
The ACLU Presents: NSA Surveillance and More ALEX ABDO STAFF ATTORNEY, ACLU NATIONAL SECURITY PROJECT CATHERINE CRUMP STAFF ATTORNEY, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, ACLU SPEECH PRIVACY & TECHNOLOGY PROJECT KADE CROCKFORD ACLU OF MASSACHUSETTS TECHNOLOGY FOR LIBERTY PROJECT NICOLE OZER TECHNOLOGY AND CIVIL LIBERTIES POLICY DIRECTOR, ACLU OF CALIFORNIA From the NSA's PRISM and....
|
Hacking Driverless Vehicles ZOZ CANNYTROPHIC DESIGN Are driverless vehicles ripe for the hacking? Autonomous and unmanned systems are already patrolling our skies and oceans and being tested on our streets and highways. All trends indicate these systems are at an inflection point that will show them rapidly becoming commonplace. It is therefore a salient time for a discussion of the capabilities and potential vulnerabilities of these sy....
|
Android WebLogin: Google's Skeleton Key CRAIG YOUNG VERT SECURITY RESEARCHER, TRIPWIRE Millions of businesses worldwide trust in Google Apps to run their organization's domain. The life-blood of these organizations is routinely stored with Google accounts and accessed with mobile devices. This talk explores how an adversary can parlay the compromise of a single Android device into a complete Google apps domain takeover. The attack vecto....
|
Android WebLogin: Google's Skeleton Key CRAIG YOUNG VERT SECURITY RESEARCHER, TRIPWIRE Millions of businesses worldwide trust in Google Apps to run their organization's domain. The life-blood of these organizations is routinely stored with Google accounts and accessed with mobile devices. This talk explores how an adversary can parlay the compromise of a single Android device into a complete Google apps domain takeover. The attack vecto....
|
BYOD PEAP Show JOSH YAVOR ISEC PARTNERS The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no long....
|
BYOD PEAP Show JOSH YAVOR ISEC PARTNERS The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no long....
|
Reality Hackers REBECCA WEXLER DIRECTOR/PRODUCER YALE VISUAL LAW PROJECT PAUL SANDERSON DIRECTOR/PRODUCER OUR TOWN FILMS Reality Hackers. Technology, wit, and hacker culture fuse in an electrified movement for digital freedom. Meet the activists who make and break technology to ensure free speech and private communication for political dissidents, and to combat global censorship. This film gives a behind-the-scenes look at those who a....
|
|
Mark Weatherford - The Growing Irrelevance of US Government Cybersecurity Intelligence Information
-
media.defcon.org
-
13 years ago
-
eng
The Growing Irrelevance of US Government Cybersecurity Intelligence Information MARK WEATHERFORD PRINCIPAL, THE CHERTOFF GROUP The rapidly changing threat landscape has finally provided relevant business justification for commercial companies to invest in developing cybersecurity intelligence that used to be the domain of the government – and they are doing it at a pace that is making the value of government “Classified" cybersecurity i....
|
|
Mark Weatherford - The Growing Irrelevance of US Government Cybersecurity Intelligence Information
-
media.defcon.org
-
13 years ago
-
eng
The Growing Irrelevance of US Government Cybersecurity Intelligence Information MARK WEATHERFORD PRINCIPAL, THE CHERTOFF GROUP The rapidly changing threat landscape has finally provided relevant business justification for commercial companies to invest in developing cybersecurity intelligence that used to be the domain of the government – and they are doing it at a pace that is making the value of government “Classified" cybersecurity i....
|
HTTP Time Bandit VAAGN TOUKHARIAN PRINCIPAL ENGINEER, QUALYS TIGRAN GEVORGYAN ENGINEERING MANAGER, QUALYS While web applications have become richer to provide a higher level user experience, they run increasingly large amounts of code on both the server and client sides. A few of the pages on the web server may be performance bottlenecks. Identifying those pages gives both application owners as well as potential attackers the chance t....
|
|
Marc Weber Tobias and Tobias Bluzmanis - Insecurity - A Failure of Imagination
-
www.defcon.org
-
13 years ago
-
eng
Insecurity - A Failure of Imagination MARC WEBER TOBIAS INVESTIGATIVE ATTORNEY AND SECURITY SPECIALIST, SECURITY.ORG TOBIAS BLUZMANIS SECURITY SPECIALIST, SECURITY.ORG Homeowners, apartment complexes, and businesses throughout the United States and Canada have purchased locks from one of the leading manufacturers in the country in the belief that they were secure. Advertising represents they are the highest grade of residential securi....
|
|
Marc Weber Tobias and Tobias Bluzmanis - Insecurity - A Failure of Imagination
-
media.defcon.org
-
13 years ago
-
eng
Insecurity - A Failure of Imagination MARC WEBER TOBIAS INVESTIGATIVE ATTORNEY AND SECURITY SPECIALIST, SECURITY.ORG TOBIAS BLUZMANIS SECURITY SPECIALIST, SECURITY.ORG Homeowners, apartment complexes, and businesses throughout the United States and Canada have purchased locks from one of the leading manufacturers in the country in the belief that they were secure. Advertising represents they are the highest grade of residential securi....
|
|
Jacob Thompson - C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood
-
www.defcon.org
-
13 years ago
-
eng
C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood JACOB THOMPSON Common wisdom dictates that web applications serving sensitive data must use an encrypted connection (i.e., HTTPS) to protect data in transit. Once served, that same sensitive data must be protected at rest, either through encryption, or more appropriately by not storing the sensitive data on disk at all. In the past, web browser disk caching policies maintained a ....
|
|
Jacob Thompson - C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood
-
media.defcon.org
-
13 years ago
-
eng
C.R.E.A.M. Cache Rules Evidently Ambiguous, Misunderstood JACOB THOMPSON Common wisdom dictates that web applications serving sensitive data must use an encrypted connection (i.e., HTTPS) to protect data in transit. Once served, that same sensitive data must be protected at rest, either through encryption, or more appropriately by not storing the sensitive data on disk at all. In the past, web browser disk caching policies maintained a ....
|
|
Josh 'm0nk' Thomas - BoutiqueKit: Playing WarGames with expensive rootkits and malware
-
www.defcon.org
-
13 years ago
-
eng
BoutiqueKit: Playing WarGames with expensive rootkits and malware JOSH 'M0NK' THOMAS APPLIED RESEARCH SCIENTIST - ACCUVANT "Theoretical" targeted rootkits need to play by different rules than the common malware that ends up filling our inboxes with spam and attempting to steal our CC numbers... The costs involved of getting popped are huge in comparison, the value is in the secrecy of being truly hidden and embedded for the long term. ....
|
|
Josh 'm0nk' Thomas - BoutiqueKit: Playing WarGames with expensive rootkits and malware
-
media.defcon.org
-
13 years ago
-
eng
BoutiqueKit: Playing WarGames with expensive rootkits and malware JOSH 'M0NK' THOMAS APPLIED RESEARCH SCIENTIST - ACCUVANT "Theoretical" targeted rootkits need to play by different rules than the common malware that ends up filling our inboxes with spam and attempting to steal our CC numbers... The costs involved of getting popped are huge in comparison, the value is in the secrecy of being truly hidden and embedded for the long term. ....
|
|
Richard Thieme - The Government and UFOs: A Historical Analysis by Richard Thieme
-
www.defcon.org
-
13 years ago
-
eng
The Government and UFOs: A Historical Analysis by Richard Thieme RICHARD THIEME This talk is about the ways the many components of governments interact and respond to challenging and anomalous events--highly relevant to hacking by all definitions and at all levels. If you donít know the lay of the land, you can not engage in appropriate research and reconnaissance, counter-measures, and operations. The proliferation of reliable repor....
|
|
Richard Thieme - The Government and UFOs: A Historical Analysis by Richard Thieme
-
media.defcon.org
-
13 years ago
-
eng
The Government and UFOs: A Historical Analysis by Richard Thieme RICHARD THIEME This talk is about the ways the many components of governments interact and respond to challenging and anomalous events--highly relevant to hacking by all definitions and at all levels. If you donít know the lay of the land, you can not engage in appropriate research and reconnaissance, counter-measures, and operations. The proliferation of reliable repor....
|
EDS: Exploitation Detection System AMR THABET MALWARE RESEARCHER, Q-CERT In the last several years, exploits have become the strongest weapons in cyber warfare. Exploit developers and vulnerability researchers have now become the nuclear scientists of the digital world. OS Companies and third party companies have created several security mitigation tools to make it harder to use these vulnerabilities and have made exploit creation harde....
|