|
This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..
|
|
Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....
|
|
This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..
|
|
Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....
|
|
This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..
|
|
Peter Eckersley & Jesse Burns - An Observatory for the SSLiverse
-
www.defcon.org
-
15 years ago
-
eng
This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....
|
|
It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..
|
|
Peter Eckersley & Jesse Burns - An Observatory for the SSLiverse
-
www.defcon.org
-
15 years ago
-
eng
This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....
|
|
It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..
|
|
Peter Eckersley & Jesse Burns - An Observatory for the SSLiverse
-
www.defcon.org
-
15 years ago
-
eng
This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....
|
|
It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..
|
|
Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....
|
|
Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....
|
|
Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....
|
|
Rich Smith - pyREtic - In-memory Reverse Engineering for Obfuscated Python Bytecode
-
www.defcon.org
-
15 years ago
-
eng
Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....
|
|
Richard Thieme - Getting Root: Remote Viewing, Non-Local Consciousness, Big Picture Hacking, and Knowing Who You Are
-
www.defcon.org
-
15 years ago
-
eng
Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....
|
|
Rich Smith - pyREtic - In-memory Reverse Engineering for Obfuscated Python Bytecode
-
www.defcon.org
-
15 years ago
-
eng
Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....
|
|
Richard Thieme - Getting Root: Remote Viewing, Non-Local Consciousness, Big Picture Hacking, and Knowing Who You Are
-
www.defcon.org
-
15 years ago
-
eng
Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....
|
|
Rich Smith - pyREtic - In-memory Reverse Engineering for Obfuscated Python Bytecode
-
www.defcon.org
-
15 years ago
-
eng
Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....
|
|
Richard Thieme - Getting Root: Remote Viewing, Non-Local Consciousness, Big Picture Hacking, and Knowing Who You Are
-
www.defcon.org
-
15 years ago
-
eng
Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....
|
|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
This presentation will be a follow up to my "Air Traffic Control: Insecurity and ADS-B" talk last year. I will give a quick overview of what has changed since last year. I will cover a few insecurity's today. How bad is your network when the FAA requires firewalls between critical flight systems and passengers surfing the web on the new 787 plane. I give a caution to all the executive jet owners that it will be much easier to track flights...
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Riley Repko - Enough Cyber Talk Already! Help Get this Collaboration Engine Running!
-
www.defcon.org
-
15 years ago
-
eng
With the Private-sector "owning" the intellectual capital for the cyber domain, one key issue is how can we extend the reach of the military's arm to leverage our requirements process, the awareness to existing or the 'art of the possible' cyber capabilities, and finally, 'non-standard' models in acquisition of cyber services? How do we capture/manage cyber cross-domain capabilities to "what's out there" in the private sector that are mutua....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Rob Ragan & Francis Brown - Lord of the Bing: Taking Back Search Engine Hacking from Google and Bing
-
www.defcon.org
-
15 years ago
-
eng
During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the teamís resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provid....
|
|
Passive DNS replication is a technique invented by Florian Weimer for tracking changes to the domain name system. This session will introduce the problems faced by passive DNS replication in the areas of collection, analysis, and storage of DNS data at scale, and will introduce state-of-the-art solutions to these problems developed at ISC SIE. Components of SIE's passive DNS architecture will be showcased, including a specialized DNS captur....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
Ryan Linn - Multiplayer Metasploit: Tag-Team Penetration and Information Gathering
-
www.defcon.org
-
15 years ago
-
eng
Sharing information in team penetration testing environments is frequently a challenge. There are a number of tools out there that allow wiki style submissions but any time that data needs to be used, it must be copied and pasted out of one form into another. Metasploit has a robust database with much of the data that a security professional may need to perform new tasks, as well as to check on the status of where the team is as a whole. Th....
|
|
What is IPv6? Why should you care? If we ignore it, will it just go away? The current Internet Protocol numbering scheme, IPv4, is nearing its end-of-life. Within two years, all the IPv4 numbers will be allocated, so that new devices will not be able to connect directly to the Internet. We all will be forced to adapt to the new IPv6 system soon. But how can we get started? This talk explains why IPv6 is necessary, how it works, an....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|
|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|