|
Blake Self, Durandal & Bitemytaco: Free Anonymous Internet Using Modified Cable Modems
-
www.defcon.org
-
17 years ago
-
eng
Using various modifications and techniques - it is possible to gain free and anonymous cable modem internet access. This talk will analyze and discuss the tools, techniques, and technology behind both hacking cable modems and attempting to catch the users who are hacking cable modems. Previously confidential information gained from a senior network technician at Time Warner will be disclosed in this speech. We will also talk about how these....
|
|
With webapp protection now mandated by the PCI standard, web-application firewalls (WAFs) have received newfound interest from both consumers of security technologies, as well as from security researchers and potential attackers. Now that WAFs are a PCI-approved substitute for code reviews, expect many vendors to opt for this potentially less costly route to compliance. Of course, security researchers and potential attacks will increasingly....
|
|
With webapp protection now mandated by the PCI standard, web-application firewalls (WAFs) have received newfound interest from both consumers of security technologies, as well as from security researchers and potential attackers. Now that WAFs are a PCI-approved substitute for code reviews, expect many vendors to opt for this potentially less costly route to compliance. Of course, security researchers and potential attacks will increasingly....
|
|
Atlas: VulnCatcher: Fun with Vtrace and Programmatic Debugging
-
www.defcon.org
-
17 years ago
-
eng
Countless hours are spent researching vulnerabilities in proprietary and open source software for each bug found. Many indicators of potential vulnerabilities are visible both in the disassembly and debugging, if you know what to look for. How much can be automated? VulnCatcher illustrates the power of programmatic debugging using the VTRACE libraries for cross-platform debugging. atlas a disciple of the illustrious Skodo, has a histor..
|
|
Atlas: VulnCatcher: Fun with Vtrace and Programmatic Debugging
-
www.defcon.org
-
17 years ago
-
eng
Countless hours are spent researching vulnerabilities in proprietary and open source software for each bug found. Many indicators of potential vulnerabilities are visible both in the disassembly and debugging, if you know what to look for. How much can be automated? VulnCatcher illustrates the power of programmatic debugging using the VTRACE libraries for cross-platform debugging. atlas a disciple of the illustrious Skodo, has a histor..
|
|
Anthony Martinez & Thomas Bowen : Toasterkit, a modular NetBSD rootkit.
-
www.defcon.org
-
17 years ago
-
eng
NetBSD is a portable operating system for just about every architecture available. There is a notable lack of tools available for the penetration tester. In this talk we will present Toasterkit, a generic NetBSD rootkit. It has been tested on i386, Mac PPC, and VAX systems. Anthony Martinez is a system administrator for the New Mexico Tech Computer Center, and an undergraduate Computer Science student at the university. Thomas B..
|
|
Anthony Martinez & Thomas Bowen : Toasterkit, a modular NetBSD rootkit.
-
www.defcon.org
-
17 years ago
-
eng
NetBSD is a portable operating system for just about every architecture available. There is a notable lack of tools available for the penetration tester. In this talk we will present Toasterkit, a generic NetBSD rootkit. It has been tested on i386, Mac PPC, and VAX systems. Anthony Martinez is a system administrator for the New Mexico Tech Computer Center, and an undergraduate Computer Science student at the university. Thomas B..
|
|
Anton Kapela & Alex Pilosov: Stealing The Internet - A Routed, Wide-area, Man in the Middle Attack
-
www.defcon.org
-
17 years ago
-
eng
In this presentation we're going to show Defcon how broken the Internet is, how helpless its users are without provider intervention, and how much apathy there is towards routing security. With the method described in this talk, an attacker is able to gain full control and visibility of all IP packets heading towards an arbitrary destination prefix on the Internet. From the perspective of the victims network, every inbound packet they....
|
|
Anton Kapela & Alex Pilosov: Stealing The Internet - A Routed, Wide-area, Man in the Middle Attack
-
www.defcon.org
-
17 years ago
-
eng
In this presentation we're going to show Defcon how broken the Internet is, how helpless its users are without provider intervention, and how much apathy there is towards routing security. With the method described in this talk, an attacker is able to gain full control and visibility of all IP packets heading towards an arbitrary destination prefix on the Internet. From the perspective of the victims network, every inbound packet they....
|
|
This presentation will cover a variety of topics of interest to anyone on a cellphone network in the US. I'm going to cover how to use your own backends for MMS and WAP access, unlock Bluetooth tethering, and circumvent some of the more obnoxious carrier restrictions. Of course, the best part is baking your own firmware and running your own code. I'll provide an overview of the processes necessary to do so, a quick rundown of what you can....
|
|
This presentation will cover a variety of topics of interest to anyone on a cellphone network in the US. I'm going to cover how to use your own backends for MMS and WAP access, unlock Bluetooth tethering, and circumvent some of the more obnoxious carrier restrictions. Of course, the best part is baking your own firmware and running your own code. I'll provide an overview of the processes necessary to do so, a quick rundown of what you can....
|
|
Adam Bregenzer: Buying Time- What is your Data Worth? ( A generalized Solution to distributed Brute Force attacks)
-
www.defcon.org
-
17 years ago
-
eng
Brute Force attacks are often marginalized as a user issue or discounted as a non-issue because of sufficient password complexity. Because rainbow tables have provided a re-invigoration of this type of attack, maintaining password security is simply not enough. In this session, I will be releasing a framework for easily creating a brute force attack tool that is both multithreaded and distributed across multiple machines. As computing power....
|
|
Adam Bregenzer: Buying Time- What is your Data Worth? ( A generalized Solution to distributed Brute Force attacks)
-
www.defcon.org
-
17 years ago
-
eng
Brute Force attacks are often marginalized as a user issue or discounted as a non-issue because of sufficient password complexity. Because rainbow tables have provided a re-invigoration of this type of attack, maintaining password security is simply not enough. In this session, I will be releasing a framework for easily creating a brute force attack tool that is both multithreaded and distributed across multiple machines. As computing power....
|
|
The Dark Tangent & Joe "Kingpin" Grand: Welcome & Making of the Badge Talk
-
www.defcon.org
-
17 years ago
-
eng
The Dark Tangent welcomes the Defcon 16 attendees at the start of the conference. For the third year in a row, Kingpin has had the honor of designing the DEFCON Badge. No longer just a boring piece of passive material, the badge is now a full-featured, active electronic product. If you're up early enough and interested in details of the entire development process of the badge, from initial concept drawings to prototype electronics to c....
|
|
The Dark Tangent & Joe "Kingpin" Grand: Welcome & Making of the Badge Talk
-
www.defcon.org
-
17 years ago
-
eng
The Dark Tangent welcomes the Defcon 16 attendees at the start of the conference. For the third year in a row, Kingpin has had the honor of designing the DEFCON Badge. No longer just a boring piece of passive material, the badge is now a full-featured, active electronic product. If you're up early enough and interested in details of the entire development process of the badge, from initial concept drawings to prototype electronics to c....
|
|
The full power of Oracle’s diagnostic events, part 1: Syntax for KSD debug event handling
-
tanelpoder.com
-
17 years ago
-
eng
There’s a recent thread in Oracle-L about deadlocks and a recommendation to dump various instance information when the deadlock happens. A deadlock trace dumps some useful things automatically, but sometimes you want more, especially in RAC environment. So is it possible to make Oracle dump additional things when the deadlock event happens? Yes it is and it’s doable with Oracle diagnostic event handling infrastructure. First I’ll take....
|
|
The full power of Oracle’s diagnostic events, part 1: Syntax for KSD debug event handling
-
tanelpoder.com
-
17 years ago
-
eng
There’s a recent thread in Oracle-L about deadlocks and a recommendation to dump various instance information when the deadlock happens. A deadlock trace dumps some useful things automatically, but sometimes you want more, especially in RAC environment. So is it possible to make Oracle dump additional things when the deadlock event happens? Yes it is and it’s doable with Oracle diagnostic event handling infrastructure. First I’ll take....
|
|
Cool, just discovered: if you’re using the (UNIX command-line program) “less” to view a file, you can hit the “v” character to open the file in “vi”!
|
|
Being a geek, I’ve always liked the word 'metric.’ A metric is a number or other quantitative object (physicists like 'metric tensors’) which measures something. I have three paintings drying right now (i.e., too wet to work into without screwing up areas). A thought occurred to me as I was thinking about what to work on next, that the number of drying paintings could be a metric of how artistically busy you happen to be at the moment. C....
|
|
Being a geek, I’ve always liked the word 'metric.’ A metric is a number or other quantitative object (physicists like 'metric tensors’) which measures something. I have three paintings drying right now (i.e., too wet to work into without screwing up areas). A thought occurred to me as I was thinking about what to work on next, that the number of drying paintings could be a metric of how artistically busy you happen to be at the moment. C....
|
|
My friends at ProgramUtvikling just published the first PodCast in the series Oslo Developer Conversations. In this PodCast, yours truly interviews Uncle Bob about software craftsmanship. The podcast is still only available as video, but audio will come shortly. I had a great time doing this interview and I’m particularly happy that we managed to have a good combination of a technical discussion and an informal discussion. I’m looking forwa..
|
|
It might strike you odd that I’m libertarian - that is, I want government as small and harmless as possible - and that my political view is rooted deeply in my faith. You see, I believe God gave us a gift, a gift so very precious that we have created a government to protect it. The government has often mishandled this gift, and so have we. We don’t really deserve this gift, but we have it.
|
|
ZFS is all about performance (many levels of caching, pre-fetch, …) and memory consumption :-) Here are my last links about ZFS [internals](http://src.opensolaris.org/source/xref/onnv/onnv- gate/usr/src/cmd/mdb/common/modules/zfs/zfs.c#333), it’s worth a read if you plan to use ZFS on large productions : The slides of Adam Leventhal’s talk for the OpenSolaris Storage Summit : ZFS, Cache, and Flash c0t0d0s0.org : a very good explanation of t..
|
|
60000 bind variables?! Maybe it’s time to use a temporary table instead…
-
tanelpoder.com
-
17 years ago
-
eng
I just noticed a bug 8277300 filed in Metalink with following description: ORA-7445[XTYQBCB] OCCURS DURING EXECUTING SQL THAT USES 60000 BIND VARIABLES . Wow! That’s about 100 times more bind variables in a single query than what I’ve seen in past. And I thought that query was bad!!! :) I suspect this is a massive IN list passed to a query. Maybe it’s time to use a temporary table or a collection for passing in the IN values instead?
|
|
60000 bind variables?! Maybe it’s time to use a temporary table instead…
-
tanelpoder.com
-
17 years ago
-
eng
I just noticed a bug 8277300 filed in Metalink with following description: ORA-7445[XTYQBCB] OCCURS DURING EXECUTING SQL THAT USES 60000 BIND VARIABLES . Wow! That’s about 100 times more bind variables in a single query than what I’ve seen in past. And I thought that query was bad!!! :) I suspect this is a massive IN list passed to a query. Maybe it’s time to use a temporary table or a collection for passing in the IN values instead?
|
|
The sky is falling. Everyone’s losing their job. The dollar isn’t worth what it used to be. Everything’s doom and gloom. Yet economists and politicians seem to insist that this is all part of a cycle, which includes recessions, booms, depressions, bull markets, bear markets, and other mumbo jumbo.
|
|
We all know that cigarettes and alcohol can be expensive because states will tax the hell out of time. Currently, California has virtually no money, and one politician has come up with a solution: tax recreational marijuana.
|
|
Five unit testing tips #4: Don't mock your way into accidental complexity
-
jhannes.github.io
-
17 years ago
-
eng
I’ve all but stopped using mock objects in my tests. The reason is that mocking have had a detrimental effect on the design of my systems. I’ve often ended up having the mocks trick me into adding a needless layer of indirection that does nothing except delegate to the next layer, just to satisfy the mocks. For a while, I was wondering whether I was the only one with this problem, but then I saw this tutorial on JBehave, which so perfectly ..
|
|
Or in other words, how to translate SQL_ID to a hash value :) I once wrote a script to demo this in my Advanced Oracle Troubleshooting class. Check this, I’ll run a query and then check what is its SQL_ID and HASH_VALUE from V$SQL: SQL> select * from dual ; D - X SQL> select sql_id, hash_value from v$sql 2 where sql_text = ' select * from dual '; SQL_ID HASH_VALUE ------------- ---------- a5ks9fhw2v9s1 942515969 So, V$SQL..
|
|
Or in other words, how to translate SQL_ID to a hash value :) I once wrote a script to demo this in my Advanced Oracle Troubleshooting class. Check this, I’ll run a query and then check what is its SQL_ID and HASH_VALUE from V$SQL: SQL> select * from dual ; D - X SQL> select sql_id, hash_value from v$sql 2 where sql_text = ' select * from dual '; SQL_ID HASH_VALUE ------------- ---------- a5ks9fhw2v9s1 942515969 So, V$SQL..
|
|
Cuba Street Fair, Wellington At the end of a few days here in Wellington, I am flying home today. This is one of my favorite cities in the world. It has been fabulous to see Neil and Amelia again, to go shopping (the US dollar is finally stronger after several years in the gutter), to go to art galleries and to walk up and down Cuba Street . Yesterday we braved the crowds at the Cuba Street Carnival, then came home and made dinne....
|
|
Cuba Street Fair, Wellington At the end of a few days here in Wellington, I am flying home today. This is one of my favorite cities in the world. It has been fabulous to see Neil and Amelia again, to go shopping (the US dollar is finally stronger after several years in the gutter), to go to art galleries and to walk up and down Cuba Street . Yesterday we braved the crowds at the Cuba Street Carnival, then came home and made dinne....
|
|
Cuba Street Fair, Wellington At the end of a few days here in Wellington, I am flying home today. This is one of my favorite cities in the world. It has been fabulous to see Neil and Amelia again, to go shopping (the US dollar is finally stronger after several years in the gutter), to go to art galleries and to walk up and down Cuba Street . Yesterday we braved the crowds at the Cuba Street Carnival, then came home and made dinne....
|
|
Welcome to my blog! Bear with us here, were just now getting the site set up, getting the kinks and the bugs out of the system.
|
|
In NAT mode (the default one), virtualbox does not give you the possibility to directly connect to your guest os. Here is how to configure your Virtualbox to simply ssh myguest For example my guest is called “Solaris10u6”, configured to used e1000 card, the default in solaris configuration, (The host os is a Mac). Type this command in terminal: `VBoxManage setextradata Solaris10u6 “VBoxInternal/Devices/e1000/0/LUN#0/Config/ssh/Protocol” TCP..
|
|
From the autodie manual : It is better to die() than to return() in failure. — Klingon programming proverb. (“die” in perl is like throwing an exception.) (via $foo magazin )
|
|
Monday morning and Jan, Timo and I are on the Northbound train from Christchurch to Picton. Outside, greens and browns of grasses, dry scrub, and trees blur together with grey skies, rain and the dun coats of sheep. It always seems to rain during my train trips here. It’s hard to believe that just Friday morning we were at the South Pole. Thursday night, having Bag Dragged and then sweated in the sauna ('Epic’ was how colleague St....
|
|
Monday morning and Jan, Timo and I are on the Northbound train from Christchurch to Picton. Outside, greens and browns of grasses, dry scrub, and trees blur together with grey skies, rain and the dun coats of sheep. It always seems to rain during my train trips here. It’s hard to believe that just Friday morning we were at the South Pole. Thursday night, having Bag Dragged and then sweated in the sauna ('Epic’ was how colleague St....
|
|
Monday morning and Jan, Timo and I are on the Northbound train from Christchurch to Picton. Outside, greens and browns of grasses, dry scrub, and trees blur together with grey skies, rain and the dun coats of sheep. It always seems to rain during my train trips here. It’s hard to believe that just Friday morning we were at the South Pole. Thursday night, having Bag Dragged and then sweated in the sauna ('Epic’ was how colleague St....
|
As part of my chess goal for 2009 I’m am working on entering as many tournaments as possible. My first one was a 6 round 25+5 at The Manukau Institute of Technology on the Saturday after Waitangi Day. The venue is close to the Otara Markets so my partner dropped me off and went shopping … Continue reading MIT Waitangi Rapid – 7 Feb 2009
|
|
Just a quick one-liner to let everyone know I’m safely in New Zealand enjoying oxygen- and moisture-rich air. Will post photos and more details tomorrow or as time allows.
|
|
This Thursday I attended a Twestival organized by jenleereeves and finally got to meet up with a ton of local “tweeters” I’ve followed for quite a while as well as meet several for the first time. In addition to finally meeting face to face, we also bid on auction items for charity:water. Good times plus helping support a good cause. I have to say it was a really awesome experience… an interesting mix of local tech heads, photographers, jou..
|
|
Just a quick one-liner to let everyone know I’m safely in New Zealand enjoying oxygen- and moisture-rich air. Will post photos and more details tomorrow or as time allows.
|