De-Anonymizing Alt.Anonymous.Messages TOM RITTER In recent years, new encryption programs like Tor, RedPhone, TextSecure, Cryptocat, and others have taken the spotlight - but the old guard of remailers and shared inboxes are still around. Alt.Anonymous.Messages is a stream of thousands of anonymous, encrypted messages, seemingly opaque to investigators. For the truly paranoid, there is no communication system that has better anonymity ....
|
|
Peiter Mudge Zatko - Unexpected Stories From a Hacker Who Made it Inside the Government
-
media.defcon.org
-
12 years ago
-
eng
Unexpected Stories From a Hacker Who Made it Inside the Government PEITER MUDGE ZATKO Having had the opportunity to see things from within the hacker community and from a senior position in the DoD, Mudge has some enlightening stories to share, and is picking some of his favorites. He'll discuss Julian's story to him about US government involvement in the origins of Wikileaks, how the DoD accidentally caused Anonymous to target governm..
|
|
Peiter Mudge Zatko - Unexpected Stories From a Hacker Who Made it Inside the Government
-
media.defcon.org
-
12 years ago
-
eng
Unexpected Stories From a Hacker Who Made it Inside the Government PEITER MUDGE ZATKO Having had the opportunity to see things from within the hacker community and from a senior position in the DoD, Mudge has some enlightening stories to share, and is picking some of his favorites. He'll discuss Julian's story to him about US government involvement in the origins of Wikileaks, how the DoD accidentally caused Anonymous to target governm..
|
|
Drea London and Kyle O'Meara - This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps
-
www.defcon.org
-
12 years ago
-
eng
This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps DREA LONDON DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG KYLE O'MEARA DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG Prior to 2013, the phrase 'Self Destructing Message' was most commonly associated with Inspector Gadget, Maxwell Smart, and the occasional Tom Cruise movie. With the advent of smartphone apps like Snapchat, Wickr, and F....
|
|
Drea London and Kyle O'Meara - This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps
-
media.defcon.org
-
12 years ago
-
eng
This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps DREA LONDON DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG KYLE O'MEARA DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG Prior to 2013, the phrase 'Self Destructing Message' was most commonly associated with Inspector Gadget, Maxwell Smart, and the occasional Tom Cruise movie. With the advent of smartphone apps like Snapchat, Wickr, and F....
|
Made Open: Hacking Capitalism TODD BONNEWELL MAN WITH A MESSAGE, MADEOPEN.COM The game is Capitalism. The rule makers are the banks, corporations and governments. This presentation is about playing a game that is rigged by the rule makers, and winning in such fashion that the game is never the same. If you like breaking things and building them back up, or are a person, please at least watch this at a later time. I forgive you for no..
|
|
Panel - Hardware Hacking with Microcontrollers: A Panel Discussion
-
media.defcon.org
-
12 years ago
-
eng
Hardware Hacking with Microcontrollers: A Panel Discussion JOE GRAND MARK 'SMITTY' SMITH LOST RENDERMAN FIRMWAREZ Microcontrollers and embedded systems come in many shapes, sizes and flavors. From tiny 6-pin devices with only a few bytes of RAM (ala the DEF CON 14 Badge) to 32- bit, eight core multiprocessor systems (ala DEF CON 20 Badge), each has their own strengths and weaknesses. Engineers and designers tend to have the....
|
|
Panel - Hardware Hacking with Microcontrollers: A Panel Discussion
-
media.defcon.org
-
12 years ago
-
eng
Hardware Hacking with Microcontrollers: A Panel Discussion JOE GRAND MARK 'SMITTY' SMITH LOST RENDERMAN FIRMWAREZ Microcontrollers and embedded systems come in many shapes, sizes and flavors. From tiny 6-pin devices with only a few bytes of RAM (ala the DEF CON 14 Badge) to 32- bit, eight core multiprocessor systems (ala DEF CON 20 Badge), each has their own strengths and weaknesses. Engineers and designers tend to have the....
|
Blucat: Netcat For Bluetooth JOSEPH PAUL COHEN TCP/IP has tools such as nmap and netcat to explore devices and create socket connections. Bluetooth has sockets but doesn't have the same tools. Blucat fills this need for the Bluetooth realm. Blucat can be thought of as a: debugging tool for bluetooth applications device exploration tool a component in building other applications Blucat is designed to run on many different platfo....
|
Blucat: Netcat For Bluetooth JOSEPH PAUL COHEN TCP/IP has tools such as nmap and netcat to explore devices and create socket connections. Bluetooth has sockets but doesn't have the same tools. Blucat fills this need for the Bluetooth realm. Blucat can be thought of as a: debugging tool for bluetooth applications device exploration tool a component in building other applications Blucat is designed to run on many different platfo....
|
|
Alex Stamos - An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet
-
media.defcon.org
-
12 years ago
-
eng
An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet ALEX STAMOS CO-FOUNDER AND CTO, ISEC PARTNERS The information security world is constantly buffeted by the struggle between whitehats, blackhats, antisec, greenhats, anarchists, statists and dozens of other self-identified interest groups. While much of this internecine conflict is easily dismissed as "InfoSec Drama", the noise of inter....
|
|
Alex Stamos - An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet
-
media.defcon.org
-
12 years ago
-
eng
An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet ALEX STAMOS CO-FOUNDER AND CTO, ISEC PARTNERS The information security world is constantly buffeted by the struggle between whitehats, blackhats, antisec, greenhats, anarchists, statists and dozens of other self-identified interest groups. While much of this internecine conflict is easily dismissed as "InfoSec Drama", the noise of inter....
|
How to use CSP to stop XSS KENNETH LEE PRODUCT SECURITY ENGINEER, ETSY INC. Crosssite scripting attacks have always been a mainstay of the OWASP Top 10 list. The problem with detecting XSS is that you can't go looking at web log traffic to determine if a request contains an actual cross site scripting attack attempt, much less one that will actually succeed against your defenses. Our work has helped reveal some nuances with implementing....
|
How to use CSP to stop XSS KENNETH LEE PRODUCT SECURITY ENGINEER, ETSY INC. Crosssite scripting attacks have always been a mainstay of the OWASP Top 10 list. The problem with detecting XSS is that you can't go looking at web log traffic to determine if a request contains an actual cross site scripting attack attempt, much less one that will actually succeed against your defenses. Our work has helped reveal some nuances with implementing....
|
|
James Denaro - How to Disclose or Sell an Exploit Without Getting in Trouble
-
www.defcon.org
-
12 years ago
-
eng
How to Disclose or Sell an Exploit Without Getting in Trouble JAMES DENARO PARTNER, CIPHERLAW You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This 20-minute session will cover the legal risks to security researchers involved in publishing or selling information that detail....
|
|
James Denaro - How to Disclose or Sell an Exploit Without Getting in Trouble
-
media.defcon.org
-
12 years ago
-
eng
How to Disclose or Sell an Exploit Without Getting in Trouble JAMES DENARO PARTNER, CIPHERLAW You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This 20-minute session will cover the legal risks to security researchers involved in publishing or selling information that detail....
|
|
Panel - Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock
-
www.defcon.org
-
12 years ago
-
eng
Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock DAVID LAWRENCE STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ERIC VAN ALBERT STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ROBERT JOHNSON STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY The Schlage Primus is one of the most common high-security locks in the United States. We reverse-engineered the operation of this lock, constructed a parameterized 3d mo....
|
|
Panel - Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock
-
media.defcon.org
-
12 years ago
-
eng
Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock DAVID LAWRENCE STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ERIC VAN ALBERT STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ROBERT JOHNSON STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY The Schlage Primus is one of the most common high-security locks in the United States. We reverse-engineered the operation of this lock, constructed a parameterized 3d mo....
|
DEF CON Comedy Jam Part VI, Return of the Fail DAVID MORTMAN CHIEF SECURITY ARCHITECT, ENSTRATIUS RICH MOGULL ANALYST & CEO, SECUROSIS CHRIS HOFF RATIONAL SECURITY DAVE MAYNOR ERRATA LARRY PESCE PAULDOTCOM.COM ENERNEX JAMES ARLEN LIQUIDMATRIX / LEVIATHAN SECURITY ROB GRAHAM ERRATA ALEX ROTHMAN SHOSTACK, ESQ. You know you can't stay away! The most talked about panel at DEF CON! More FAIL than you can shake a stick at. Come ....
|
DEF CON Comedy Jam Part VI, Return of the Fail DAVID MORTMAN CHIEF SECURITY ARCHITECT, ENSTRATIUS RICH MOGULL ANALYST & CEO, SECUROSIS CHRIS HOFF RATIONAL SECURITY DAVE MAYNOR ERRATA LARRY PESCE PAULDOTCOM.COM ENERNEX JAMES ARLEN LIQUIDMATRIX / LEVIATHAN SECURITY ROB GRAHAM ERRATA ALEX ROTHMAN SHOSTACK, ESQ. You know you can't stay away! The most talked about panel at DEF CON! More FAIL than you can shake a stick at. Come ....
|
|
Brandon Wiley - Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine
-
media.defcon.org
-
12 years ago
-
eng
Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine BRANDON WILEY RESEARCHER, STEP THREE: PROFIT! The greatest danger to free speech on the Internet today is filtering of traffic using protocol fingerprinting. Protocols such as SSL, Tor, BitTorrent, and VPNs are being summarily blocked, regardless of their legal and ethical uses. Fortunately, it is possible to bypass this filtering by reencoding traffic into a form ....
|
Prowling Peer-to-Peer Botnets After Dark TILLMANN WERNER CROWDSTRIKE, INC. Peer-to-peer botnets have become the backbone of the cybercrime ecosystem. Due to their distributed nature, they are more difficult to understand and contain than traditional botnets. To combat this problem, we have developed the open-source framework *prowler* for peer-to-peer botnet tracking and node enumeration. It combines efficient crawling strategies with t....
|
|
Christopher Soghoian - Backdoors, Government Hacking and The Next Crypto Wars
-
media.defcon.org
-
12 years ago
-
eng
Backdoors, Government Hacking and The Next Crypto Wars CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, PRIVACY & TECHNOLOGY PROJECT, ACLU The FBI claims it is going dark. Encryption technologies have finally been deployed by software companies, and critically, enabled by default, such that emails are flowing over HTTPS, and disk encryption is now frequently used. Friendly telcos, who were once a one-stop-shop for surveillance can no longer....
|
|
Christopher Soghoian - Backdoors, Government Hacking and The Next Crypto Wars
-
media.defcon.org
-
12 years ago
-
eng
Backdoors, Government Hacking and The Next Crypto Wars CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, PRIVACY & TECHNOLOGY PROJECT, ACLU The FBI claims it is going dark. Encryption technologies have finally been deployed by software companies, and critically, enabled by default, such that emails are flowing over HTTPS, and disk encryption is now frequently used. Friendly telcos, who were once a one-stop-shop for surveillance can no longer....
|
|
Ryan W. Smith and Tim Strazzere - DragonLady: An Investigation of SMS Fraud Operations in Russia
-
media.defcon.org
-
12 years ago
-
eng
DragonLady: An Investigation of SMS Fraud Operations in Russia RYAN W. SMITH SENIOR RESEARCH AND RESPONSE ENGINEER, LOOKOUT MOBILE SECURITY TIM STRAZZERE LEAD RESEARCH AND RESPONSE ENGINEER, LOOKOUT MOBILE SECURITY One of the top types of Android malware are trojans that claim to provide a useful service, but instead send SMS messages to premium shortcodes, charging the victims and putting money directly into the attackers’ hands. We’....
|
|
Ryan W. Smith and Tim Strazzere - DragonLady: An Investigation of SMS Fraud Operations in Russia
-
media.defcon.org
-
12 years ago
-
eng
DragonLady: An Investigation of SMS Fraud Operations in Russia RYAN W. SMITH SENIOR RESEARCH AND RESPONSE ENGINEER, LOOKOUT MOBILE SECURITY TIM STRAZZERE LEAD RESEARCH AND RESPONSE ENGINEER, LOOKOUT MOBILE SECURITY One of the top types of Android malware are trojans that claim to provide a useful service, but instead send SMS messages to premium shortcodes, charging the victims and putting money directly into the attackers’ hands. We’....
|
The Dark Arts of OSINT NOAH SCHIFFMAN SKYDOG The proliferation and availability of public information has increased with the evolution of its dissemination. With the constant creation of digital document archives and the migration towards a paperless society, vast databases of information are continuously being generated. Collectively, these publicly available databases contain enough specific information to pose certain vulnerabili....
|
The Dark Arts of OSINT NOAH SCHIFFMAN SKYDOG The proliferation and availability of public information has increased with the evolution of its dissemination. With the constant creation of digital document archives and the migration towards a paperless society, vast databases of information are continuously being generated. Collectively, these publicly available databases contain enough specific information to pose certain vulnerabili....
|
|
Nicholas J. Percoco and Joshua Corman - The Cavalry Isn't Coming: Starting the Revolution to Fsck it All!
-
www.defcon.org
-
12 years ago
-
eng
The Cavalry Isn't Coming: Starting the Revolution to Fsck it All! NICHOLAS J. PERCOCO SENIOR VICE PRESIDENT AND HEAD OF SPIDERLABS, TRUSTWAVE JOSHUA CORMAN DIRECTOR OF SECURITY INTELLIGENCE, AKAMAI TECHNOLOGIES We have some good news and some bad news. The good news is that security is now top of mind for the people of planet Earth. The bad news is that their security illiteracy has lead to very dangerous precedents and this is likel....
|
|
Nicholas J. Percoco and Joshua Corman - The Cavalry Isn't Coming: Starting the Revolution to Fsck it All!
-
media.defcon.org
-
12 years ago
-
eng
The Cavalry Isn't Coming: Starting the Revolution to Fsck it All! NICHOLAS J. PERCOCO SENIOR VICE PRESIDENT AND HEAD OF SPIDERLABS, TRUSTWAVE JOSHUA CORMAN DIRECTOR OF SECURITY INTELLIGENCE, AKAMAI TECHNOLOGIES We have some good news and some bad news. The good news is that security is now top of mind for the people of planet Earth. The bad news is that their security illiteracy has lead to very dangerous precedents and this is likel....
|
|
Charlie Miller and Chris Valasek - Adventures in Automotive Networks and Control Units
-
media.defcon.org
-
12 years ago
-
eng
Adventures in Automotive Networks and Control Units CHARLIE MILLER SECURITY ENGINEER, TWITTER CHRIS VALASEK DIRECTOR OF SECURITY INTELLIGENCE AT IOACTIVE, INC. Automotive computers, or Electronic Control Units (ECU), were originally introduced to help with fuel efficiency and emissions problems of the 1970s but evolved into integral parts of in-car entertainment, safety controls, and enhanced automotive functionality. This presentatio....
|
|
Charlie Miller and Chris Valasek - Adventures in Automotive Networks and Control Units
-
media.defcon.org
-
12 years ago
-
eng
Adventures in Automotive Networks and Control Units CHARLIE MILLER SECURITY ENGINEER, TWITTER CHRIS VALASEK DIRECTOR OF SECURITY INTELLIGENCE AT IOACTIVE, INC. Automotive computers, or Electronic Control Units (ECU), were originally introduced to help with fuel efficiency and emissions problems of the 1970s but evolved into integral parts of in-car entertainment, safety controls, and enhanced automotive functionality. This presentatio....
|
|
Sean Malone - HiveMind: Distributed File Storage Using JavaScript Botnets
-
media.defcon.org
-
12 years ago
-
eng
HiveMind: Distributed File Storage Using JavaScript Botnets SEAN MALONE PRINCIPAL SECURITY CONSULTANT, FUSIONX Some data is too sensitive or volatile to store on systems you own. What if we could store it somewhere else without compromising the security or availability of the data, while leveraging intended functionality to do so? This presentation will cover the methodology and tools required to create a distributed file store built on....
|
|
Sean Malone - HiveMind: Distributed File Storage Using JavaScript Botnets
-
media.defcon.org
-
12 years ago
-
eng
HiveMind: Distributed File Storage Using JavaScript Botnets SEAN MALONE PRINCIPAL SECURITY CONSULTANT, FUSIONX Some data is too sensitive or volatile to store on systems you own. What if we could store it somewhere else without compromising the security or availability of the data, while leveraging intended functionality to do so? This presentation will cover the methodology and tools required to create a distributed file store built on....
|
|
Adam Laurie and Zac Franken - Decapping Chips the Easy Hard Way
-
media.defcon.org
-
12 years ago
-
eng
Decapping Chips the Easy Hard Way ADAM "MAJOR MALFUNCTION" LAURIE CODE MONKEY, APERTURE LABS ZAC FRANKEN CHIP MONKEY, APERTURE LABS For some time it has been possible to discover the inner workings of microprocessors with the help of a microscope and some nasty chemicals such as fuming nitric acid. However, unless you have access to a university or work science lab, this is beyond the reach of most hackers, and, even it were to be att....
|
|
Adam Laurie and Zac Franken - Decapping Chips the Easy Hard Way
-
media.defcon.org
-
12 years ago
-
eng
Decapping Chips the Easy Hard Way ADAM "MAJOR MALFUNCTION" LAURIE CODE MONKEY, APERTURE LABS ZAC FRANKEN CHIP MONKEY, APERTURE LABS For some time it has been possible to discover the inner workings of microprocessors with the help of a microscope and some nasty chemicals such as fuming nitric acid. However, unless you have access to a university or work science lab, this is beyond the reach of most hackers, and, even it were to be att....
|
|
David Kennedy and Nick Hitchcock - The Dirty South – Getting Justified with Technology
-
media.defcon.org
-
12 years ago
-
eng
The Dirty South – Getting Justified with Technology DAVID KENNEDY FOUNDER & PRINCIPAL SECURITY CONSULTANT, TRUSTEDSEC NICK HITCHCOCK SENIOR SECURITY CONSULTANT, TRUSTEDSEC It seems that every day there's a new NextGen firewall, whitelisting and blacklisting, DLP, or the latest technology thats suppose to stop us. But does it really stop "hackers"? Truth is, naw not really. In this talk we'll be showing off the latest bypass techniq....
|
|
David Kennedy and Nick Hitchcock - The Dirty South – Getting Justified with Technology
-
media.defcon.org
-
12 years ago
-
eng
The Dirty South – Getting Justified with Technology DAVID KENNEDY FOUNDER & PRINCIPAL SECURITY CONSULTANT, TRUSTEDSEC NICK HITCHCOCK SENIOR SECURITY CONSULTANT, TRUSTEDSEC It seems that every day there's a new NextGen firewall, whitelisting and blacklisting, DLP, or the latest technology thats suppose to stop us. But does it really stop "hackers"? Truth is, naw not really. In this talk we'll be showing off the latest bypass techniq....
|
|
Daniel Burroughs - Open Public Sensors, Trend Monitoring and Data Fusion
-
media.defcon.org
-
12 years ago
-
eng
Open Public Sensors, Trend Monitoring and Data Fusion DANIEL BURROUGHS ASSOCIATE DIRECTOR OF TECHNOLOGY, CENTER FOR LAW ENFORCEMENT TECHNOLOGY, TRAINING AND RESEARCH Our world is instrumented with countless sensors. While many are outside of our direct control, there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fas....
|
|
Daniel Burroughs - Open Public Sensors, Trend Monitoring and Data Fusion
-
media.defcon.org
-
12 years ago
-
eng
Open Public Sensors, Trend Monitoring and Data Fusion DANIEL BURROUGHS ASSOCIATE DIRECTOR OF TECHNOLOGY, CENTER FOR LAW ENFORCEMENT TECHNOLOGY, TRAINING AND RESEARCH Our world is instrumented with countless sensors. While many are outside of our direct control, there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fas....
|
|
Doug DePerry and Tom Ritter - I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell
-
www.defcon.org
-
12 years ago
-
eng
I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell DOUG DEPERRY SENIOR SECURITY CONSULTANT, ISEC PARTNERS TOM RITTER SENIOR SECURITY CONSULTANT, ISEC PARTNERS I have a box on my desk that your CDMA cell phone will automatically connect to while you send and receive phone calls, text messages, emails, and browse the Internet. I own this box. I watch all the traffic that crosses it....
|
|
Doug DePerry and Tom Ritter - I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell
-
media.defcon.org
-
12 years ago
-
eng
I Can Hear You Now: Traffic Interception and Remote Mobile Phone Cloning with a Compromised CDMA Femtocell DOUG DEPERRY SENIOR SECURITY CONSULTANT, ISEC PARTNERS TOM RITTER SENIOR SECURITY CONSULTANT, ISEC PARTNERS I have a box on my desk that your CDMA cell phone will automatically connect to while you send and receive phone calls, text messages, emails, and browse the Internet. I own this box. I watch all the traffic that crosses it....
|