|
Windows .NET Server is Microsoft's new contender against Linux in the server market. Scheduled for release in 2003, .NET Server (which was originally released for beta testing under the codename "Whistler") is re-engineered from the Windows 2000 Server codebase. .NET Server's survival will probably depend on how users perceive its security. Bill Gates himself realized this when he released his "Trustworthy Computing" memo in Jan. 2002. His ....
|
|
Dr. Walter C. Daugherity - Quantum Computing 101: How to Crack RSA
-
defcon.org
-
16 years ago
-
eng
The brand-new technology of quantum computers offers the prospect of exponential speedup, making heretofore infeasible problems like cracking RSA conceiveable. The fundamentals of quantum computing are presented, and how a quantum computer could be used to crack RSA is described. Dr. Walter C. Daugherity is a Senior Lecturer in Computer Science and Electrical Engineering at Texas A&M University. He received a bachelor's degree from Okl..
|
|
Covert Channels in TCP and IP Headers How would you communicate securely in a country where encryption is outlawed or where key escrow is mandatory? How can you prevent the Feds from forcing you to turn over your encryption keys? Simple. Don't let your adversaries know that you're transmitting encrypted information. Using covert channels you can completely hide the fact that you're transmitting encrypted information. During this presen..
|
|
Covert Channels in TCP and IP Headers How would you communicate securely in a country where encryption is outlawed or where key escrow is mandatory? How can you prevent the Feds from forcing you to turn over your encryption keys? Simple. Don't let your adversaries know that you're transmitting encrypted information. Using covert channels you can completely hide the fact that you're transmitting encrypted information. During this presen..
|
|
DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..
|
|
DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..
|
|
This talk is primarily about psychology and relates to typical programming in no way. Neuro-Linguistic Programming is best described as new age pseudo science by some and the future of psychology to others. Through this talk on NLP you will learn about the ability to control and otherwise manipulate as well as teaching via "knowledge encoded linguistic algorithms." You should also gain the ability to do a "cold read." You will also lea..
|
|
This talk is primarily about psychology and relates to typical programming in no way. Neuro-Linguistic Programming is best described as new age pseudo science by some and the future of psychology to others. Through this talk on NLP you will learn about the ability to control and otherwise manipulate as well as teaching via "knowledge encoded linguistic algorithms." You should also gain the ability to do a "cold read." You will also lea..
|
|
This is a fingerprinting library designed to bring together the fingerprinting capabilities of NMAP, QueSO and X (at least version 1). Using this library you should be able to add operating system sensitive code to your favorite Perl, Java, C or C++ code. At the most basic level the goal of this library is to provide a mechanism so that you can add code to your programs that reads if(OS.Family == Windows Family) { 'do something'} ....
|
|
This is a fingerprinting library designed to bring together the fingerprinting capabilities of NMAP, QueSO and X (at least version 1). Using this library you should be able to add operating system sensitive code to your favorite Perl, Java, C or C++ code. At the most basic level the goal of this library is to provide a mechanism so that you can add code to your programs that reads if(OS.Family == Windows Family) { 'do something'} ....
|
|
Servers, workstations and PCs are the common targets of an average attacker, but there is much more to find in todays networks. Every device that has a processor, some memory and a network interface can become a target. Using printers and other common devices as examples, we will show how to exploit design failures and vulnerabilities and use the target as an attack platform. We will also release some tools, methods and sample code to enter..
|
|
Servers, workstations and PCs are the common targets of an average attacker, but there is much more to find in todays networks. Every device that has a processor, some memory and a network interface can become a target. Using printers and other common devices as examples, we will show how to exploit design failures and vulnerabilities and use the target as an attack platform. We will also release some tools, methods and sample code to enter..
|
|
Gingerbread Man - Lock Picking: Techniques and Tools for High Security
-
defcon.org
-
16 years ago
-
eng
The talk will cover current techniques used for picking locks such as mushroom pin tumblers, medeco, abloy, and tubular locks. The talk will also cover how to formulate attacks on new locks. I am a self taught hobbyist. I have five years experience in amateur locksmithing. I am currently attending a Canadian University as a Computer Science major.
|
|
Gingerbread Man - Lock Picking: Techniques and Tools for High Security
-
defcon.org
-
16 years ago
-
eng
The talk will cover current techniques used for picking locks such as mushroom pin tumblers, medeco, abloy, and tubular locks. The talk will also cover how to formulate attacks on new locks. I am a self taught hobbyist. I have five years experience in amateur locksmithing. I am currently attending a Canadian University as a Computer Science major.
|
|
Wolves Among Us GOBBLES Security members will be giving a presentation called "Wolves Among Us", which will discuss the evil motivations of certain members and organizations of the security industry, the big companies that are underqualified for security and yet reap such incredible revenue for their services, the way the media is uninformed and further intentionally writes incorrect information concerning hackers, and more. Concrete e..
|
|
Wolves Among Us GOBBLES Security members will be giving a presentation called "Wolves Among Us", which will discuss the evil motivations of certain members and organizations of the security industry, the big companies that are underqualified for security and yet reap such incredible revenue for their services, the way the media is uninformed and further intentionally writes incorrect information concerning hackers, and more. Concrete e..
|
|
Gregory S. Miles - Anatomy of Denial of Service Mitigation Testing
-
defcon.org
-
16 years ago
-
eng
DOC has had the privilege of working on a project that was focused on looking at new product technologies relating to DOS and DDOS mitigation. Several commercial companies were formed who's entire focus was to find solutions to DOS and DDOS issues. Different types of detection were used in each product from pure rate analysis to statistical analysis and anomaly detection. This talk will focus on the testing methodology, testing results, les....
|
|
Gregory S. Miles - Anatomy of Denial of Service Mitigation Testing
-
defcon.org
-
16 years ago
-
eng
DOC has had the privilege of working on a project that was focused on looking at new product technologies relating to DOS and DDOS mitigation. Several commercial companies were formed who's entire focus was to find solutions to DOS and DDOS issues. Different types of detection were used in each product from pure rate analysis to statistical analysis and anomaly detection. This talk will focus on the testing methodology, testing results, les....
|
|
Selling Out For Fun and Profit Recent events in the security industry have caused multiple groups to cry foul and claim that many so called hackers have sold out. A war of words has errupted between those crying foul and those who have apparently sold out. Most recently, Gweeds presented a talk at H2K2 that touched on many nerves when he pointed fingers at specific people in the security industry. While the talk given by Gweeds wa....
|
|
Selling Out For Fun and Profit Recent events in the security industry have caused multiple groups to cry foul and claim that many so called hackers have sold out. A war of words has errupted between those crying foul and those who have apparently sold out. Most recently, Gweeds presented a talk at H2K2 that touched on many nerves when he pointed fingers at specific people in the security industry. While the talk given by Gweeds wa....
|
|
The talk will discuss the backgroup, current architecture and use the LIDS. And also will talk about what kind of attacks LIDS can detect and prevent and finally will get into details how to build a secure linux system with LIDS. Huagang Xie, the author of the open source (GPL) LIDS project, is a kernel hacker and linux enthusiast. Gradudated from Tsinghua University and Insititue of Computing Techology of Chinese Academy of Sciences,h..
|
|
The talk will discuss the backgroup, current architecture and use the LIDS. And also will talk about what kind of attacks LIDS can detect and prevent and finally will get into details how to build a secure linux system with LIDS. Huagang Xie, the author of the open source (GPL) LIDS project, is a kernel hacker and linux enthusiast. Gradudated from Tsinghua University and Insititue of Computing Techology of Chinese Academy of Sciences,h..
|
|
IDSs have traditionally been seen as purely information resources, requiring human intervention in order to act on alerts. Recently, support for modifying firewall rules and killing active connections have begun to appear in IDSs, but these suffer from shortcomings. A desire has been recently expressed by many people for an active, 'Gateway' IDS (GIDS), allowing filtering and routing of traffic to be performed by a gateway computer using bo..
|
|
IDSs have traditionally been seen as purely information resources, requiring human intervention in order to act on alerts. Recently, support for modifying firewall rules and killing active connections have begun to appear in IDSs, but these suffer from shortcomings. A desire has been recently expressed by many people for an active, 'Gateway' IDS (GIDS), allowing filtering and routing of traffic to be performed by a gateway computer using bo..
|
|
Citrix and Terminal Services are becoming very popular. Ian Vitek will speak about: # Scanning and finding Terminal Services and Published Applications. This will include statistics of open and vulnerable servers. # Connection to Published Applications. This can be harder than you think. Most of the servers have Published Applications. You can’t just see them. # Breaking out from the given environment and elevation of rights. # Demo..
|
|
Citrix and Terminal Services are becoming very popular. Ian Vitek will speak about: # Scanning and finding Terminal Services and Published Applications. This will include statistics of open and vulnerable servers. # Connection to Published Applications. This can be harder than you think. Most of the servers have Published Applications. You can’t just see them. # Breaking out from the given environment and elevation of rights. # Demo..
|
|
A prudent System Administrator will review system logs. While performing this log analysis, administrators may detect nefarious activity of various types (port probes, exploit attempts, DOS/DDOS). Of course, what you receive in the system logs doesn't contain the offender's name and telephone number. Rather, most Firewalls and Intrusion Detection Systems will log an IP address, or at best, a reverse DNS lookup of the IP address. This presen....
|
|
A prudent System Administrator will review system logs. While performing this log analysis, administrators may detect nefarious activity of various types (port probes, exploit attempts, DOS/DDOS). Of course, what you receive in the system logs doesn't contain the offender's name and telephone number. Rather, most Firewalls and Intrusion Detection Systems will log an IP address, or at best, a reverse DNS lookup of the IP address. This presen....
|
|
The Unix FTP servers have been called 'the IIS of the Unix world' for their frequent and potent vulnerabilities. Each has provided remote exploits, usually at the root privilege level, on a consistent and frequent basis. WU-FTPd is the most popular Unix FTP server by far, shipping by default on most Linux distributions, and even on Solaris, and being installed most commonly on the rest of the Unix platforms. This talk will demonstrate worki....
|
|
The Unix FTP servers have been called 'the IIS of the Unix world' for their frequent and potent vulnerabilities. Each has provided remote exploits, usually at the root privilege level, on a consistent and frequent basis. WU-FTPd is the most popular Unix FTP server by far, shipping by default on most Linux distributions, and even on Solaris, and being installed most commonly on the rest of the Unix platforms. This talk will demonstrate worki....
|
|
Jay Beale - Bastille Linux 2.0: Six Operating Systems and Still Going!
-
defcon.org
-
16 years ago
-
eng
Bastille Linux is a security tightening program that has proven capable of thwarting or containing many of the vulnerabilities discovered in operating systems. Originally written for Red Hat Linux, Bastille has now been ported to six operating systems, including HP-UX. This talk will talk about what Bastille does, what we've done to it in the last year, and what we're working on next. Most importantly, it will teach you something about hard....
|
|
Jay Beale - Bastille Linux 2.0: Six Operating Systems and Still Going!
-
defcon.org
-
16 years ago
-
eng
Bastille Linux is a security tightening program that has proven capable of thwarting or containing many of the vulnerabilities discovered in operating systems. Originally written for Red Hat Linux, Bastille has now been ported to six operating systems, including HP-UX. This talk will talk about what Bastille does, what we've done to it in the last year, and what we're working on next. Most importantly, it will teach you something about hard....
|
|
John L. Dodge - Should Organizations Employ Hackers? Implications Drawn From the Book Hacking of America
-
defcon.org
-
16 years ago
-
eng
This DefCon10 presentation, while drawing from the study, will discuss the implications of employing hackers in the work place. The book Hacking of America (Greenwood, 2002) reports on the Laurentian University study of the hacker community and in particular the conference participants of DefCon8 and H2K. The study data was collected though a 20 page self-report questionnaire completed by hackers at these conferences. It was also supplement....
|
|
John L. Dodge - Should Organizations Employ Hackers? Implications Drawn From the Book Hacking of America
-
defcon.org
-
16 years ago
-
eng
This DefCon10 presentation, while drawing from the study, will discuss the implications of employing hackers in the work place. The book Hacking of America (Greenwood, 2002) reports on the Laurentian University study of the hacker community and in particular the conference participants of DefCon8 and H2K. The study data was collected though a 20 page self-report questionnaire completed by hackers at these conferences. It was also supplement....
|
|
I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..
|
|
I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..
|
|
Ken Caruso - Community Wireless Networks, Friend or Foe to the Telecom Industry
-
defcon.org
-
16 years ago
-
eng
Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..
|
|
Ken Caruso - Community Wireless Networks, Friend or Foe to the Telecom Industry
-
defcon.org
-
16 years ago
-
eng
Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..
|
|
SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....
|
|
SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....
|
|
Lucky Green - Trusted Computing Platform Alliance: The mother(board) of All Big Brothers
-
defcon.org
-
16 years ago
-
eng
The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....
|
|
Lucky Green - Trusted Computing Platform Alliance: The mother(board) of All Big Brothers
-
defcon.org
-
16 years ago
-
eng
The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....
|
|
Michael Glasser - High Security Locks, and Access Control Products
-
defcon.org
-
16 years ago
-
eng
The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..
|
|
Michael Glasser - High Security Locks, and Access Control Products
-
defcon.org
-
16 years ago
-
eng
The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..
|