|
This session introduces and demonstrates the emerging attack vector of psychosonics. Attend and you'll understand how to turn ANY MP3 into a weapon, a study aid, a hidden calming session or helping you experience that Ah-Ha moment of discovery simply by injecting an alternate data stream attack made up of psychosonic frequencies. You'll learn how different mental states can be created using frequencies that interact with the brain, how....
|
|
This session introduces and demonstrates the emerging attack vector of psychosonics. Attend and you'll understand how to turn ANY MP3 into a weapon, a study aid, a hidden calming session or helping you experience that Ah-Ha moment of discovery simply by injecting an alternate data stream attack made up of psychosonic frequencies. You'll learn how different mental states can be created using frequencies that interact with the brain, how....
|
|
An in depth forensic analysis of video games and the systems they're played on. The goal of which is to identify the types of information useful to a forensics investigation and any other bits of personal information. Brandon Nesbit is a Security Consultant at Trustwave. He is a member of Trustwave's SpiderLabs - the advanced security team focused on penetration testing, incident response, and application security. Brandon has 9 years ..
|
|
Bruce Potter & Logan Lodge - This Needs to be Fixed, and Other Jokes in Commit Statements
-
www.defcon.org
-
15 years ago
-
eng
Open source. These two words mean lots of things to lots of people. Some say, because it's open source it's more secure because you have complete transparency. Some say, because it's open source it's less secure because amateurs are writing the code. Well, one thing is true, with open source you have free reign to see the code and all the commentary left in there before it's compiled away. Ever wondered what was in those comments? Is there ....
|
|
An in depth forensic analysis of video games and the systems they're played on. The goal of which is to identify the types of information useful to a forensics investigation and any other bits of personal information. Brandon Nesbit is a Security Consultant at Trustwave. He is a member of Trustwave's SpiderLabs - the advanced security team focused on penetration testing, incident response, and application security. Brandon has 9 years ..
|
|
Bruce Potter & Logan Lodge - This Needs to be Fixed, and Other Jokes in Commit Statements
-
www.defcon.org
-
15 years ago
-
eng
Open source. These two words mean lots of things to lots of people. Some say, because it's open source it's more secure because you have complete transparency. Some say, because it's open source it's less secure because amateurs are writing the code. Well, one thing is true, with open source you have free reign to see the code and all the commentary left in there before it's compiled away. Ever wondered what was in those comments? Is there ....
|
|
An in depth forensic analysis of video games and the systems they're played on. The goal of which is to identify the types of information useful to a forensics investigation and any other bits of personal information. Brandon Nesbit is a Security Consultant at Trustwave. He is a member of Trustwave's SpiderLabs - the advanced security team focused on penetration testing, incident response, and application security. Brandon has 9 years ..
|
|
Bruce Potter & Logan Lodge - This Needs to be Fixed, and Other Jokes in Commit Statements
-
www.defcon.org
-
15 years ago
-
eng
Open source. These two words mean lots of things to lots of people. Some say, because it's open source it's more secure because you have complete transparency. Some say, because it's open source it's less secure because amateurs are writing the code. Well, one thing is true, with open source you have free reign to see the code and all the commentary left in there before it's compiled away. Ever wondered what was in those comments? Is there ....
|
|
On April 14, 2009 Microsoft released a patch (http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx) to fix the issues detailed in my previous Token Kidnapping presentation (http://www.argeniss.com/research/TokenKidnapping.pdf). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the....
|
|
On April 14, 2009 Microsoft released a patch (http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx) to fix the issues detailed in my previous Token Kidnapping presentation (http://www.argeniss.com/research/TokenKidnapping.pdf). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the....
|
|
On April 14, 2009 Microsoft released a patch (http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx) to fix the issues detailed in my previous Token Kidnapping presentation (http://www.argeniss.com/research/TokenKidnapping.pdf). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the....
|
|
Due to the prevalence of spammers on the internet CAPTCHAs have become a necessary security measure. Without a CAPTCHA in place a system is incapable of knowing whether a human or an automated computer is executing a request. Currently one of the most widely implemented versions of this system is Google's reCAPTCHA due to its robustness thus far. This paper illustrates techniques to defeat this system which has been trusted to secure websit....
|
|
Due to the prevalence of spammers on the internet CAPTCHAs have become a necessary security measure. Without a CAPTCHA in place a system is incapable of knowing whether a human or an automated computer is executing a request. Currently one of the most widely implemented versions of this system is Google's reCAPTCHA due to its robustness thus far. This paper illustrates techniques to defeat this system which has been trusted to secure websit....
|
|
Due to the prevalence of spammers on the internet CAPTCHAs have become a necessary security measure. Without a CAPTCHA in place a system is incapable of knowing whether a human or an automated computer is executing a request. Currently one of the most widely implemented versions of this system is Google's reCAPTCHA due to its robustness thus far. This paper illustrates techniques to defeat this system which has been trusted to secure websit....
|
|
Charlie Miller - Kim Jong-il and Me: How to Build a Cyber Army to Defeat the U.S.
-
www.defcon.org
-
15 years ago
-
eng
Think you might ever be "asked" by a dictator of an Axis of Evil country to take down the USA in a cyberwar? Ever wonder how someone who finds vulnerabilities and breaks into computers for a living would approach cyberwar, i.e. not Richard Clarke? Then this is the talk for you! In this talk, I outline how to construct a cyber army to attack a developed country, based on my experience as a penetration tester and security researcher. This wil....
|
|
Chema Alonso & José Palazón "Palako" - Connection String Parameter Attacks
-
www.defcon.org
-
15 years ago
-
eng
This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credential, how to get access to this web applications impersonating the connection ....
|
|
Charlie Miller - Kim Jong-il and Me: How to Build a Cyber Army to Defeat the U.S.
-
www.defcon.org
-
15 years ago
-
eng
Think you might ever be "asked" by a dictator of an Axis of Evil country to take down the USA in a cyberwar? Ever wonder how someone who finds vulnerabilities and breaks into computers for a living would approach cyberwar, i.e. not Richard Clarke? Then this is the talk for you! In this talk, I outline how to construct a cyber army to attack a developed country, based on my experience as a penetration tester and security researcher. This wil....
|
|
Chema Alonso & José Palazón "Palako" - Connection String Parameter Attacks
-
www.defcon.org
-
15 years ago
-
eng
This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credential, how to get access to this web applications impersonating the connection ....
|
|
Charlie Miller - Kim Jong-il and Me: How to Build a Cyber Army to Defeat the U.S.
-
www.defcon.org
-
15 years ago
-
eng
Think you might ever be "asked" by a dictator of an Axis of Evil country to take down the USA in a cyberwar? Ever wonder how someone who finds vulnerabilities and breaks into computers for a living would approach cyberwar, i.e. not Richard Clarke? Then this is the talk for you! In this talk, I outline how to construct a cyber army to attack a developed country, based on my experience as a penetration tester and security researcher. This wil....
|
|
Chema Alonso & José Palazón "Palako" - Connection String Parameter Attacks
-
www.defcon.org
-
15 years ago
-
eng
This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credential, how to get access to this web applications impersonating the connection ....
|
|
Chema Alonso & José Palazón "Palako" - FOCA2: The FOCA Strikes Back
-
www.defcon.org
-
15 years ago
-
eng
FOCA is a tool to extract information in footprinting and fingerprinting phases during a penetration test. It helps auditors to extract and analyze information from metadata, hidden info and lost data in published files. This new release of FOCA, version 2, adds tools to scans internal domains using PTR Scanning, Software recognition through installation paths, etc. The idea of FOCA is to give as much info as can be discovered automatically....
|
|
Chema Alonso & José Palazón "Palako" - FOCA2: The FOCA Strikes Back
-
www.defcon.org
-
15 years ago
-
eng
FOCA is a tool to extract information in footprinting and fingerprinting phases during a penetration test. It helps auditors to extract and analyze information from metadata, hidden info and lost data in published files. This new release of FOCA, version 2, adds tools to scans internal domains using PTR Scanning, Software recognition through installation paths, etc. The idea of FOCA is to give as much info as can be discovered automatically....
|
|
Chema Alonso & José Palazón "Palako" - FOCA2: The FOCA Strikes Back
-
www.defcon.org
-
15 years ago
-
eng
FOCA is a tool to extract information in footprinting and fingerprinting phases during a penetration test. It helps auditors to extract and analyze information from metadata, hidden info and lost data in published files. This new release of FOCA, version 2, adds tools to scans internal domains using PTR Scanning, Software recognition through installation paths, etc. The idea of FOCA is to give as much info as can be discovered automatically....
|
|
Facebook's privacy issues are numerous and well-documented, from software "glitches" to decisions that take control away from users. Despite that, it is a still-growing force in the modern Internet and is currently trying to position itself as the gateway to the "social Web" for its 500 million users. What can we, as hackers, do to protect the privacy of those millions? This panel walks through a few existing projects that apply s....
|
|
If you think that RFID tags can only be read a few inches away from a reader you haven't met EPC Gen2, the tag that can be found in Enhanced Drivers Licenses - this 900MHz tag is readable from 30 feet with off-the-shelf equipment. Without amplifying the signal from a commercial reader we were able to equal the previous Defcon record of 69 feet, and with less than $1000 of equipment we achieved considerably further than that. This talk cover....
|
|
Facebook's privacy issues are numerous and well-documented, from software "glitches" to decisions that take control away from users. Despite that, it is a still-growing force in the modern Internet and is currently trying to position itself as the gateway to the "social Web" for its 500 million users. What can we, as hackers, do to protect the privacy of those millions? This panel walks through a few existing projects that apply s....
|
|
If you think that RFID tags can only be read a few inches away from a reader you haven't met EPC Gen2, the tag that can be found in Enhanced Drivers Licenses - this 900MHz tag is readable from 30 feet with off-the-shelf equipment. Without amplifying the signal from a commercial reader we were able to equal the previous Defcon record of 69 feet, and with less than $1000 of equipment we achieved considerably further than that. This talk cover....
|
|
Facebook's privacy issues are numerous and well-documented, from software "glitches" to decisions that take control away from users. Despite that, it is a still-growing force in the modern Internet and is currently trying to position itself as the gateway to the "social Web" for its 500 million users. What can we, as hackers, do to protect the privacy of those millions? This panel walks through a few existing projects that apply s....
|
|
If you think that RFID tags can only be read a few inches away from a reader you haven't met EPC Gen2, the tag that can be found in Enhanced Drivers Licenses - this 900MHz tag is readable from 30 feet with off-the-shelf equipment. Without amplifying the signal from a commercial reader we were able to equal the previous Defcon record of 69 feet, and with less than $1000 of equipment we achieved considerably further than that. This talk cover....
|
|
It's widely accepted that the cryptoscheme in GSM can be broken, but did you know that if you're within radio range of your target you can intercept all of their cellphone calls by bypassing the cryptoscheme entirely? This talk discusses the practical aspects of operating an "IMSI catcher", a fake GSM base station designed to trick the target handset into sending you its voice traffic. Band jamming, rolling LACs, Neighbour advertisements an....
|
|
It's widely accepted that the cryptoscheme in GSM can be broken, but did you know that if you're within radio range of your target you can intercept all of their cellphone calls by bypassing the cryptoscheme entirely? This talk discusses the practical aspects of operating an "IMSI catcher", a fake GSM base station designed to trick the target handset into sending you its voice traffic. Band jamming, rolling LACs, Neighbour advertisements an....
|
|
It's widely accepted that the cryptoscheme in GSM can be broken, but did you know that if you're within radio range of your target you can intercept all of their cellphone calls by bypassing the cryptoscheme entirely? This talk discusses the practical aspects of operating an "IMSI catcher", a fake GSM base station designed to trick the target handset into sending you its voice traffic. Band jamming, rolling LACs, Neighbour advertisements an....
|
|
Christopher Soghoian - Your ISP and the Government: Best Friends Forever
-
www.defcon.org
-
15 years ago
-
eng
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law enforcement and intelligence agencies. Worse, firms like Google and Microsoft specifically log data in order to assist the government, while AT&T and Verizon are paid $1.8 million per year in order to provide real time access to customer communica....
|
|
Christopher Soghoian - Your ISP and the Government: Best Friends Forever
-
www.defcon.org
-
15 years ago
-
eng
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law enforcement and intelligence agencies. Worse, firms like Google and Microsoft specifically log data in order to assist the government, while AT&T and Verizon are paid $1.8 million per year in order to provide real time access to customer communica....
|
|
Christopher Soghoian - Your ISP and the Government: Best Friends Forever
-
www.defcon.org
-
15 years ago
-
eng
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law enforcement and intelligence agencies. Worse, firms like Google and Microsoft specifically log data in order to assist the government, while AT&T and Verizon are paid $1.8 million per year in order to provide real time access to customer communica....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|