|
Marion Marschalek - A Thorny Piece Of Malware (And Me): The Nastiness of SEH, VFTables & Multi-Threading
-
media.defcon.org
-
12 years ago
-
eng
A Thorny Piece Of Malware (And Me): The Nastiness of SEH, VFTables & Multi-Threading MARION MARSCHALEK ANALYST, IKARUS SECURITY SOFTWARE GMBH Reverse Engineering is the supreme discipline in analyzing malware, how else would you find out all capabilities of a malicious sample? But this task gets trickier nearly every day, as malware authors apply new techniques to evade analysis. Even worse, documentation of said techniques is barely ex....
|
|
Wesley McGrew - Pwn The Pwn Plug: Analyzing and Counter-Attacking Attacker-Implanted Devices
-
www.defcon.org
-
12 years ago
-
eng
Pwn The Pwn Plug: Analyzing and Counter-Attacking Attacker-Implanted Devices WESLEY MCGREW RESEARCH ASSOCIATE, MISSISSIPPI STATE UNIVERSITY Malicious attackers and penetration testers alike are drawn to the ease and convenience of small, disguise-able attacker-controlled devices that can be implanted physically in a target organization. When such devices are discovered in an organization, that organization may wish to perform a forensic....
|
|
Todd Manning and Zach Lanier - GoPro or GTFO: A Tale of Reversing an Embedded System
-
www.defcon.org
-
12 years ago
-
eng
GoPro or GTFO: A Tale of Reversing an Embedded System TODD MANNING SENIOR RESEARCH CONSULTANT, ACCUVANT LABS ZACH LANIER SENIOR RESEARCH CONSULTANT, ACCUVANT LABS Embedded systems are shrinking in size and becoming widely used in many consumer devices. High quality optic sensors and lenses are also shrinking in size. The GoPro Hero 3 camera leverages high quality camera equipment with multiple embedded operating systems to offer no....
|
|
Tom Keenan - Torturing Open Government Systems for Fun, Profit and Time Travel
-
www.defcon.org
-
12 years ago
-
eng
Torturing Open Government Systems for Fun, Profit and Time Travel TOM KEENAN PROFESSOR, UNIVERSITY OF CALGARY "I'm from the government and I'm here to help you" takes on a sinister new meaning as jurisdictions around the world stumble over each other to 'set the people's data free'. NYC boasts in subway ads that 'our apps are whiz kid certified' (i.e. third party) which of course translates to 'we didn't pay for them, and don't blame us....
|
|
Dr. Tom Keenan - Torturing Open Government Systems for Fun, Profit and Time Travel
-
media.defcon.org
-
12 years ago
-
eng
Torturing Open Government Systems for Fun, Profit and Time Travel TOM KEENAN PROFESSOR, UNIVERSITY OF CALGARY "I'm from the government and I'm here to help you" takes on a sinister new meaning as jurisdictions around the world stumble over each other to 'set the people's data free'. NYC boasts in subway ads that 'our apps are whiz kid certified' (i.e. third party) which of course translates to 'we didn't pay for them, and don't blame us....
|
|
Abraham Kang and Dinis Cruz - Resting on Your Laurels will get you Pwned: Effectively Code Reviewing REST Applications to avoid getting pwned
-
www.defcon.org
-
12 years ago
-
eng
Resting on Your Laurels will get you Pwned: Effectively Code Reviewing REST Applications to avoid getting powned ABRAHAM KANG DIRECTOR OF R&D AT SAMSUNG DINIS CRUZ Public REST APIs have become mainstream. It is not just startups such as Facebook and twitter at the fore front of the REST revolution. Now, almost every company that wants to expose services or an application programming interfaces does it using a publicly exposed REST AP....
|
|
Alberto Garcia Illera and Javier Vazquez Vidal - Dude, WTF in my car?
-
www.defcon.org
-
12 years ago
-
eng
Dude, WTF in my car? ALBERTO GARCIA ILLERA JAVIER VAZQUEZ VIDAL The ECU tuning market is weird. There is little help from people in it, and most of the equipment is expensive. Well, not anymore! After hacking some equipment worth thousands of dollars, a new toy was born. Seed/Key algos broken, RSA bustedÖ We will learn all about Bosch EDC15 and EDC16 car ECUs. How they communicate, what protocols they use, their security and why it ....
|
|
Alberto Garcia Illera and Javier Vazquez Vidal - Dude, WTF in my car?
-
media.defcon.org
-
12 years ago
-
eng
Dude, WTF in my car? ALBERTO GARCIA ILLERA JAVIER VAZQUEZ VIDAL The ECU tuning market is weird. There is little help from people in it, and most of the equipment is expensive. Well, not anymore! After hacking some equipment worth thousands of dollars, a new toy was born. Seed/Key algos broken, RSA bustedÖ We will learn all about Bosch EDC15 and EDC16 car ECUs. How they communicate, what protocols they use, their security and why it ....
|
The Bluetooth Device Database RYAN HOLEMAN SENIOR SOFTWARE DEVELOPER, ZIFTEN TECHNOLOGIES As of 2013, it is estimated that there are now billions of bluetooth devices deployed worldwide. The goal of the Bluetooth Database Project is to track and freely distribute real time sightings and statistics of these wide spread devices. The data collected from these devices can be used to answer questions pertaining to various topics, such as dev....
|
The Bluetooth Device Database RYAN HOLEMAN SENIOR SOFTWARE DEVELOPER, ZIFTEN TECHNOLOGIES As of 2013, it is estimated that there are now billions of bluetooth devices deployed worldwide. The goal of the Bluetooth Database Project is to track and freely distribute real time sightings and statistics of these wide spread devices. The data collected from these devices can be used to answer questions pertaining to various topics, such as dev....
|
Phantom Network Surveillance UAV / Drone RICKY HILL SECURITY CONSULTANT DARPA, 2011, sponsored a contest named UAVForge which challenged teams to build a prototype unmanned aerial vehicle (UAV). Mission: "UAV must be small enough to fit in a soldier's rucksack and able to fly to, perch & stare from useful locations for several hours near targets of interest to provide real-time (visual) persistent surveillance." Long story short: 140 te....
|
Phantom Network Surveillance UAV / Drone RICKY HILL SECURITY CONSULTANT DARPA, 2011, sponsored a contest named UAVForge which challenged teams to build a prototype unmanned aerial vehicle (UAV). Mission: "UAV must be small enough to fit in a soldier's rucksack and able to fly to, perch & stare from useful locations for several hours near targets of interest to provide real-time (visual) persistent surveillance." Long story short: 140 te....
|
|
Justin Hendricks - So You Think Your Domain Controller is Secure?
-
www.defcon.org
-
12 years ago
-
eng
So You Think Your Domain Controller is Secure? JUSTIN HENDRICKS SECURITY ENGINEER, MICROSOFT Domain Controllers are the crown jewels of an organization. Once they fall, everything in the domain falls . Organizations go to great lengths to secure their domain controllers, however they often fail to properly secure the software used to manage these servers. This presentation will cover unconventional methods for gaining domain admin by ..
|
|
Justin Hendricks - So You Think Your Domain Controller is Secure?
-
media.defcon.org
-
12 years ago
-
eng
So You Think Your Domain Controller is Secure? JUSTIN HENDRICKS SECURITY ENGINEER, MICROSOFT Domain Controllers are the crown jewels of an organization. Once they fall, everything in the domain falls . Organizations go to great lengths to secure their domain controllers, however they often fail to properly secure the software used to manage these servers. This presentation will cover unconventional methods for gaining domain admin by ..
|
|
Dan Griffin - Protecting Data with Short-Lived Encryption Keys and Hardware Root of Trust
-
www.defcon.org
-
12 years ago
-
eng
Protecting Data with Short-Lived Encryption Keys and Hardware Root of Trust DAN GRIFFIN PRESIDENT, JW SECURE, INC. The US National Security Agency has been public about the inevitability of mobile computing and the need to support cloud-based service use for secret projects. General Alexander, head of the NSA, recently spoke of using smartphones as ID cards on classified networks. And yet, mobile devices have a poor security track rec....
|
|
Dan Griffin - Protecting Data with Short-Lived Encryption Keys and Hardware Root of Trust
-
media.defcon.org
-
12 years ago
-
eng
Protecting Data with Short-Lived Encryption Keys and Hardware Root of Trust DAN GRIFFIN PRESIDENT, JW SECURE, INC. The US National Security Agency has been public about the inevitability of mobile computing and the need to support cloud-based service use for secret projects. General Alexander, head of the NSA, recently spoke of using smartphones as ID cards on classified networks. And yet, mobile devices have a poor security track rec....
|
|
Joe Grand - JTAGulator: Assisted Discovery Of On-Chip Debug Interfaces
-
www.defcon.org
-
12 years ago
-
eng
JTAGulator: Assisted Discovery Of On-Chip Debug Interfaces JOE GRAND AKA KINGPIN On-chip debug (OCD) interfaces can provide chip-level control of a target device and are a primary vector used by hackers to extract program code or data, modify memory contents, or affect device operation on-the-fly. Depending on the complexity of the target device, manually locating available OCD connections can be a difficult and time consuming task, som....
|
|
Joe Grand - JTAGulator: Assisted Discovery Of On-Chip Debug Interfaces
-
media.defcon.org
-
12 years ago
-
eng
JTAGulator: Assisted Discovery Of On-Chip Debug Interfaces JOE GRAND AKA KINGPIN On-chip debug (OCD) interfaces can provide chip-level control of a target device and are a primary vector used by hackers to extract program code or data, modify memory contents, or affect device operation on-the-fly. Depending on the complexity of the target device, manually locating available OCD connections can be a difficult and time consuming task, som....
|
|
Brian Gorenc and Jasiel Spelman - Java Every-Days: Exploiting Software Running on 3 Billion Devices
-
www.defcon.org
-
12 years ago
-
eng
Java Every-Days: Exploiting Software Running on 3 Billion Devices BRIAN GORENC ZERO DAY INITIATIVE, HP SECURITY RESEARCH JASIEL SPELMAN SECURITY RESEARCHER Over the last three years, Oracle Java has become the exploit author's best friend. And why not? Java has a rich attack surface, broad install base, and runs on multiple platforms allowing attackers to maximize their return-on-investment. The increased focus on uncovering weaknesse....
|
|
Brian Gorenc and Jasiel Spelman - Java Every-Days: Exploiting Software Running on 3 Billion Devices
-
media.defcon.org
-
12 years ago
-
eng
Java Every-Days: Exploiting Software Running on 3 Billion Devices BRIAN GORENC ZERO DAY INITIATIVE, HP SECURITY RESEARCH JASIEL SPELMAN SECURITY RESEARCHER Over the last three years, Oracle Java has become the exploit author's best friend. And why not? Java has a rich attack surface, broad install base, and runs on multiple platforms allowing attackers to maximize their return-on-investment. The increased focus on uncovering weaknesse....
|
|
Eric Fulton and Daniel Zolnikov - The Politics of Privacy and Technology: Fighting an Uphill Battle
-
www.defcon.org
-
12 years ago
-
eng
The Politics of Privacy and Technology: Fighting an Uphill Battle ERIC FULTON CEO, SUBSECTOR SOLUTIONS DANIEL ZOLNIKOV STATE REPRESENTATIVE, MONTANA In the past few decades the world has been dramatically transformed by technology. People have significantly evolved in how they interact with each other and the world; a side effect of this evolution is the drastic change in personal privacy. Private citizens, corporations, and governmen....
|
|
Eric Fulton and Daniel Zolnikov - The Politics of Privacy and Technology: Fighting an Uphill Battle
-
media.defcon.org
-
12 years ago
-
eng
The Politics of Privacy and Technology: Fighting an Uphill Battle ERIC FULTON CEO, SUBSECTOR SOLUTIONS DANIEL ZOLNIKOV STATE REPRESENTATIVE, MONTANA In the past few decades the world has been dramatically transformed by technology. People have significantly evolved in how they interact with each other and the world; a side effect of this evolution is the drastic change in personal privacy. Private citizens, corporations, and governmen....
|
Defeating SEAndroid PAU OLIVA FORA SR. MOBILE SECURITY ENGINEER, VIAFORENSICS Security Enhancements for Android (SEAndroid) enables the use of SELinux in Android in order to limit the damage that can be done by malicious apps, trying to make exploitation harder. Some OEMs are trying hard to implement extra mitigations in their devices, especially those aiming to reach the enterprise market. We will present some issues that are found in ....
|
Defeating SEAndroid PAU OLIVA FORA SR. MOBILE SECURITY ENGINEER, VIAFORENSICS Security Enhancements for Android (SEAndroid) enables the use of SELinux in Android in order to limit the damage that can be done by malicious apps, trying to make exploitation harder. Some OEMs are trying hard to implement extra mitigations in their devices, especially those aiming to reach the enterprise market. We will present some issues that are found in ....
|
10000 Yen into the Sea FLIPPER The use of a pressure housing in an underwater vehicle can be difficult to implement without becoming a cost-center. Flipper will walk the audience through a new design for an Autonomous Underwater Glider which challenges assumptions about what is required or necessary to deploy sensors, transmitters, and payloads across long distances in the ocean. The speaker assumes no priory knowledge of subject matter....
|
10000 Yen into the Sea FLIPPER The use of a pressure housing in an underwater vehicle can be difficult to implement without becoming a cost-center. Flipper will walk the audience through a new design for an Autonomous Underwater Glider which challenges assumptions about what is required or necessary to deploy sensors, transmitters, and payloads across long distances in the ocean. The speaker assumes no priory knowledge of subject matter....
|
|
Amir Etemadieh and CJ Heres - Google TV or: How I Learned to Stop Worrying and Exploit Secure Boot
-
www.defcon.org
-
12 years ago
-
eng
Google TV or: How I Learned to Stop Worrying and Exploit Secure Boot AMIR ETEMADIEH RESEARCH SCIENTIST AT ACCUVANT LABS CJ HERES IT CONSULTANT MIKE BAKER CO-FOUNDER OPENWRT HANS NIELSEN SENIOR SECURITY CONSULTANT AT MATASANO Google TV is intended to bring the Android operating system out of the mobile environment and into consumers' living rooms. Unfortunately, content providers began to block streaming access to popular content f....
|
|
Panel - Google TV or: How I Learned to Stop Worrying and Exploit Secure Boot
-
media.defcon.org
-
12 years ago
-
eng
Google TV or: How I Learned to Stop Worrying and Exploit Secure Boot AMIR ETEMADIEH RESEARCH SCIENTIST AT ACCUVANT LABS CJ HERES IT CONSULTANT MIKE BAKER CO-FOUNDER OPENWRT HANS NIELSEN SENIOR SECURITY CONSULTANT AT MATASANO Google TV is intended to bring the Android operating system out of the mobile environment and into consumers' living rooms. Unfortunately, content providers began to block streaming access to popular content f....
|
|
Justin Engler and Paul Vines - Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO)
-
www.defcon.org
-
12 years ago
-
eng
Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO) JUSTIN ENGLER SENIOR SECURITY ENGINEER, ISEC PARTNERS PAUL VINES Password and PIN systems are often encountered on mobile devices. A software approach to cracking these systems is often the simplest, but in some cases there may be no better option than to start pushing buttons. This talk will cover automated PIN cracking techniques using two new tools....
|
|
Justin Engler and Paul Vines - Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO)
-
media.defcon.org
-
12 years ago
-
eng
Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO) JUSTIN ENGLER SENIOR SECURITY ENGINEER, ISEC PARTNERS PAUL VINES Password and PIN systems are often encountered on mobile devices. A software approach to cracking these systems is often the simplest, but in some cases there may be no better option than to start pushing buttons. This talk will cover automated PIN cracking techniques using two new tools....
|
|
Melissa Elliott - Noise Floor: Exploring the world of unintentional radio emissions
-
www.defcon.org
-
12 years ago
-
eng
Noise Floor: Exploring the world of unintentional radio emissions MELISSA ELLIOTT APPLICATION SECURITY RESEARCHER, VERACODE If it's electronic, it makes noise. Not necessarily noise that you and I can hear, of course – unless you know how to tune in. The air around us is filled with bloops, bleeps, and bzzts of machines going about their business, betraying their existence through walls or even from across the street. The unintentional ....
|
|
Melissa Elliott - Noise Floor: Exploring the world of unintentional radio emissions
-
media.defcon.org
-
12 years ago
-
eng
Noise Floor: Exploring the world of unintentional radio emissions MELISSA ELLIOTT APPLICATION SECURITY RESEARCHER, VERACODE If it's electronic, it makes noise. Not necessarily noise that you and I can hear, of course – unless you know how to tune in. The air around us is filled with bloops, bleeps, and bzzts of machines going about their business, betraying their existence through walls or even from across the street. The unintentional ....
|
|
Lt. Gen. Robert Elder - From Nukes to Cyber – Alternative Approaches for Proactive Defense and Mission Assurance
-
media.defcon.org
-
12 years ago
-
eng
From Nukes to Cyber – Alternative Approaches for Proactive Defense and Mission Assurance LT. GEN. ROBERT ELDER USAF (RETIRED) In typical military operations, the advantage goes to the offense because the initiator controls the timing and is able to concentrate forces. A good defense is designed to undermine the advantage of the offense. Proactive defense approaches include: masking (obfuscation), maneuvering, and hardening of critica....
|
|
Lt. Gen. Robert Elder - From Nukes to Cyber – Alternative Approaches for Proactive Defense and Mission Assurance
-
media.defcon.org
-
12 years ago
-
eng
From Nukes to Cyber – Alternative Approaches for Proactive Defense and Mission Assurance LT. GEN. ROBERT ELDER USAF (RETIRED) In typical military operations, the advantage goes to the offense because the initiator controls the timing and is able to concentrate forces. A good defense is designed to undermine the advantage of the offense. Proactive defense approaches include: masking (obfuscation), maneuvering, and hardening of critica....
|
Pwn'ing You(r) Cyber Offenders PIOTR DUSZYNSKI SENIOR SECURITY CONSULTANT, TRUSTWAVE SPIDERLABS It is commonly believed that Offensive Defense is just a theory that is difficult to be used effectively in practice, but that is not entirely true... During my talk along with a new service emulation technique, that will render standard port scanner results nearly useless and leave your attackers with an arduous analysis, I will focus on ....
|
Pwn'ing You(r) Cyber Offenders PIOTR DUSZYNSKI SENIOR SECURITY CONSULTANT, TRUSTWAVE SPIDERLABS It is commonly believed that Offensive Defense is just a theory that is difficult to be used effectively in practice, but that is not entirely true... During my talk along with a new service emulation technique, that will render standard port scanner results nearly useless and leave your attackers with an arduous analysis, I will focus on ....
|
Privacy In DSRC Connected Vehicles CHRISTIE DUDLEY PRIVACY LEGAL RESEARCHER To date, remote vehicle communications such as OnStar have provided little in the way of privacy. The planned DSRC system will become the first large-scale nationwide direct public participation network outside of the internet. Much information and misinformation has been spread on what the upcoming DSRC system is and can do, especially in the information securi....
|
Privacy In DSRC Connected Vehicles CHRISTIE DUDLEY PRIVACY LEGAL RESEARCHER To date, remote vehicle communications such as OnStar have provided little in the way of privacy. The planned DSRC system will become the first large-scale nationwide direct public participation network outside of the internet. Much information and misinformation has been spread on what the upcoming DSRC system is and can do, especially in the information securi....
|
Proliferation AMBASSADOR JOSEPH R. DETRANI PRESIDENT, INTELLIGENCE AND NATIONAL SECURITY ALLIANCE (INSA) Ambassador Joseph DeTrani was named President of the Intelligence and National Security Alliance (INSA) on February 5, 2013. As President, he will lead INSA as its Chief Executive Officer on a day-to-day basis. Ambassador DeTrani has dedicated his professional career to public service with more than three decades of work for ....
|
Proliferation AMBASSADOR JOSEPH R. DETRANI PRESIDENT, INTELLIGENCE AND NATIONAL SECURITY ALLIANCE (INSA) Ambassador Joseph DeTrani was named President of the Intelligence and National Security Alliance (INSA) on February 5, 2013. As President, he will lead INSA as its Chief Executive Officer on a day-to-day basis. Ambassador DeTrani has dedicated his professional career to public service with more than three decades of work for ....
|
|
Andy Davis - Revealing Embedded Fingerprints: Deriving intelligence from USB stack interactions
-
www.defcon.org
-
12 years ago
-
eng
Revealing Embedded Fingerprints: Deriving intelligence from USB stack interactions ANDY DAVIS RESEARCH DIRECTOR, NCC GROUP Embedded systems are everywhere, from TVs to aircraft, printers to weapon control systems. As a security researcher when you are faced with one of these 'black boxes' to test, sometime in-situ, it is difficult to know where to start. However, if there is a USB port on the device there is useful information that can ....
|
|
Andy Davis - Revealing Embedded Fingerprints: Deriving intelligence from USB stack interactions
-
media.defcon.org
-
12 years ago
-
eng
Revealing Embedded Fingerprints: Deriving intelligence from USB stack interactions ANDY DAVIS RESEARCH DIRECTOR, NCC GROUP Embedded systems are everywhere, from TVs to aircraft, printers to weapon control systems. As a security researcher when you are faced with one of these 'black boxes' to test, sometime in-situ, it is difficult to know where to start. However, if there is a USB port on the device there is useful information that can ....
|
Do-It-Yourself Cellular IDS SHERRI DAVIDOFF LMG SECURITY SCOTT FRETHEIM LMG SECURITY DAVID HARRISON LMG SECURITY RANDI PRICE LMG SECURITY For less than $500, you can build your own cellular intrusion detection system to detect malicious activity through your own local femtocell. Our team will show how we leveraged root access on a femtocell, reverse engineered the activation process, and turned it into a proof-of-concept cellular ....
|
Do-It-Yourself Cellular IDS SHERRI DAVIDOFF LMG SECURITY SCOTT FRETHEIM LMG SECURITY DAVID HARRISON LMG SECURITY RANDI PRICE LMG SECURITY For less than $500, you can build your own cellular intrusion detection system to detect malicious activity through your own local femtocell. Our team will show how we leveraged root access on a femtocell, reverse engineered the activation process, and turned it into a proof-of-concept cellular ....
|