|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Locks restrict access to anyone lacking the correct key. As security components, we depend on locks to secure our most valuable possessions. Most attacks demonstrated in recent years involve manipulation of the lock components with special picking tools, but what if we focused on using incorrect or blank keys to make a variety of tools? Bumping is a good example, but there are many other ways incorrect or modified keys can be used to defeat....
|
|
This talk describes how crawling BitTorrent's DHTs used for distributed tracking can be used for two opposing goals. First, pirates can crawl the DHTs to build BitTorrent search engines in just a few hours without relying on the survival of any existing search engines or trackers. Second, content owners can crawl the DHTs to monitor users' behavior at large scale. The talk will start by explaining what BitTorrent DHTs are and how they ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Merdinger - We Don't Need No Stinkin' Badges: Hacking Electronic Door Access Controllers
-
www.defcon.org
-
15 years ago
-
eng
In the security world, attacker physical access often means game over - so what happens if you can't trust your building's electronic door system? This presentation and paper explore attack surfaces and exploitation vectors in a major vendor of electronic door access controllers (EDAC). The main focus is on time-constrained rapid analysis and bug-hunting methodologies, while covering research techniques that assist in locating and targ....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
Shawn Moyer & Nathan Keltner - Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios
-
www.defcon.org
-
15 years ago
-
eng
If you haven't just emerged from a coma, you probably have some idea of the multifaceted attack surface that the inevitable modernization of power transmission and distribution is rapidly introducing What you may *not* be thinking about just yet, though, is the path much of that attack surface travels on... The air around you Our talk gives a crash course in the brain-melting number of wireless Smart Grid radio implementations ver....
|
|
Sho Ho - FOE The Release of Feed Over Email, a Solution to Feed Controversial News to Censored Countries
-
www.defcon.org
-
15 years ago
-
eng
Many repressive countries have created Internet censorship systems to prevent Internet users from accessing websites that are deemed inappropriate by their officials. In many cases, these websites are news, political, or religion websites and the main purpose for the ban is to protect the interest of the country's political parties. FOE is a new censorship circumvention tool developed in-house by the Broadcasting Board of Governors (th....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
The Suggmeister - Social Networking Special Ops: Extending Data Visualization Tools for Faster Pwnage
-
www.defcon.org
-
15 years ago
-
eng
If you're ever in a position when you need to pwn criminals via social networks or see where Tony Hawk likes to hide skateboards around the world, this talk is for you. The talk is delivered in two parts, both of which are intended to shine a fun light on visual social network analysis. The first part introduces how you can extend the powerful data visualization tool, Maltego to speed up and automate the data mining and analysis o....
|
|
This talk will focus on exploiting SQL injections in web applications with oracle back-end and will discuss all old/new techniques. The talk will target Oracle 9i,10g and 11g (R1 and R2) It is widely considered that the impact of SQL Injection in web apps with Oracle back-end is limited to extraction of data with the privileges of user mentioned in connection string. Oracle database does not offer hacker friendly functionalities such as ope....
|
|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|
|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|
|
Tom Stracener "Strace", Sean Barnum & Chris Peterson - So Many Ways to Slap A Yo-Ho:: Xploiting Yoville and Facebook for Fun and Profit
-
www.defcon.org
-
15 years ago
-
eng
Maybe you've played YoVille because your spouse or relative got you into it. Maybe its your overt obsession or secret delight. If you haven't heard of YoVille, well, its got at least 5 Million active users connected directly with Facebook.This talk explores the Web 2.0 pandora's box that is the trust relationship between YoVille and Facebook. For many, YoVille is fiercely competitive in a hyper-decorative way, it has its own intricate ....
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Want to take a stab at graffiti but spray paint fumes get you nauseous? Worry not! The world of virtual graffiti is slowly but surely gaining popularity and now hackers with little to no artistic inclination are able to go out and alter digital media as well as leave messages in virtual mediums with as much (if not more) finesse than our analogue counterparts are able to. This talk will cover the history of graffiti, how virtual graf..
|
|
JBoss is an open source Java EE application server. Its default configuration provides several insecure defaults that an attacker can use to gather information, cause a denial of service, or even execute arbitrary code on the system. Tyler Krpata Tyler Krpata is a principal security engineer for a SaaS company. He has previously worked in enterprise security in the retail and healthcare fields. When he was suspended from high school fo..
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Val Smith, Colin Ames & Anthony Lai - Balancing the Pwn Trade Deficit
-
www.defcon.org
-
15 years ago
-
eng
One of the presenters is a native Chinese language speaker and heavily involved in the Chinese security community and so brings unique insights to this presentation. The other presenters have been analyzing APT style threats for many years and bring this experience to bare on a problem that has received a lot of recent attention, but little technical depth. Viewers should walk away with a greatly increased understanding of the Chinese hacki....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wade Polk, Paul Malkewicz & J. Novak - Industrial Cyber Security
-
www.defcon.org
-
15 years ago
-
eng
Industrial control systems are flexible constructs that result in increased efficiency and profitability, but this comes at the cost of vulnerability. In past years, industrial cyber security has been mostly ignored due to cost, lack of understanding, and a low incidence rate. More and more these systems rely on commercial, off the shelf software which increases the ease and likelihood of an attack. Today, we face growing threats from indiv....
|
|
Wayne Huang - Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection
-
www.defcon.org
-
15 years ago
-
eng
This year saw the biggest news in Web security ever--Operation Aurora, which aimed at stealing source code and other intellectual properties and succeeded with more than 30 companies, including Google. Incidence response showed that the operation involved an IE 0-day drive-by-download, resulting in Google's compromise and leak of source code to jump points in Taiwan. The US Government is so concerned that they issued a demarche to the Chine....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
Wayne Huang, Jeremy Chiu & Benson Wu - 0box Analyzer: AfterDark Runtime Forensics for Automated Malware Analysis and Clustering
-
www.defcon.org
-
15 years ago
-
eng
For antivirus vendors and malware researchers today, the challenge lies not in "obtaining" the malware samples - they have too many already. What's needed is automated tools to speed up the analysis process. Many sandboxes exist for behavior profiling, but it still remains a challenge to handle anti-analysis techniques and to generate useful reports. The problem with current tools is the monitoring mechanism - there's always a "sandbox....
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
This is a short talk on NoSQL technologies and their impacts on traditional injection threats such as SQL injection. This talk surveys existing NoSQL technologies, and then demos proof-of-concept threats found with CouchDB. We then discuss impacts of NoSQL technologies to existing security technologies such as blackbox scanning, static analysis, and web application firewalls. Wayne Huang has extensive experience in the security industr..
|
|
The most fundamental difference between hash and nested loop joins
-
tanelpoder.com
-
15 years ago
-
eng
Basically the most fundamental (or biggest or most important) difference between nested loop and hash joins is that: Hash joins can not look up rows from the inner (probed) row source based on values retrieved from the outer (driving) row source, nested loops can. In other words, when joining table A and B (A is driving table, B is the probed table), then a nested loop join can take 1st row from A and perform a lookup to B using that ..
|