|
Martin Gallo - Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gallo/DEFCON-20-Gallo-Uncovering-SAP-Vulnerabilities.pdf Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol Martin Gallo Security Consultant, Core Security Nowadays, SAP Netweaver has become the most extensive platform for building enterprise applications and run critical b....
|
|
Andrew Gavin, Michael Baucom and Charles Smith Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gavin-Baucom-Smith/DEFCON-20-Gavin-Baucom-Smith-OpenDLP.pdf Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions R&D Andrew Gavin Security Consultant, Verizon Business Michael Baucom Vice President of R&D, N2 Net Security Inc. Charles Smith Software Developer, N2 Net Secur....
|
The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The establishment of US Cyber Command in 2010 confirmed that cyberspace is a new domain of warfare. Computers are now both a weapon and a target. Future wars may even be fought over the ownership of IT infrastructure. Therefore, national security thinkers must find a way to incorporate cyber attack and defense into military doctrine as soon as possible. The world’s mo....
|
More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program that followed the real-life design process of a unique prototype every episode. At DEF CON 17, Joe and Zoz talked about the show and a few of their favorite builds. The dynamic nerd duo returns to....
|
Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA has been advocating the adoption of measured boot and hardware-based integrity checks. But what does this trend mean to the open source and hacker communities? In this talk I'll demonstrate measured b....
|
Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Microsoft Exchange to allow people to check their corporate emails or sync their calendars remotely. Exchange has an interesting relationship with its mobile clients. It demands a certain level of control over the devices, enforcing policy such as password complexity, screen timeouts, remote lock out and....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....
|
Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive monitoring framework, a project was launched to produce this functionality. Through this functionality, a new means for interactively observing bluetooth was created along with Python APIs to assist in the development of bluetooth auditing, pentesting and exploitation tools. The project sup....
|
Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on this problem. It seems amazing that reflective injection still works. Why is that? Because programmers are lazy. They don't want to write new engines, they want to write definitions for an engi....
|
|
James Kirk - An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets
-
www.defcon.org
-
13 years ago
-
eng
An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets James Kirk Senior Security Consultant / Rapid7, Inc. With an ever changing threat of nation states targeting the United States and its infrastructure and insiders stealing information for public release, we must continuously evaluate the procedural and technical controls we place on our national assets. T....
|
|
Xeno Kovah and Corey Kallenberg - No More Hooks: Detection of Code Integrity Attacks
-
www.defcon.org
-
13 years ago
-
eng
No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For instance code can be "inlined hooked" by rewriting instructions to unconditionally transfer to other code. Or code can be hooked by manipulating control flow data like function pointers (IAT, IDT, SSDT, retur....
|
DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VXRL Enterprises currently dump millions of bucks to defense against DDoS, some trading firms here are paying for fear to the DDoS attack from China about 5K to 100K USD per day and InfoSec teams believe....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....
|
|
James Kirk - An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....
|
|
Xeno Kovah and Corey Kallenberg - No More Hooks: Detection of Code Integrity Attacks
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....
|
|
James Kirk - An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....
|
|
Xeno Kovah and Corey Kallenberg - No More Hooks: Detection of Code Integrity Attacks
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....
|
|
Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....
|
|
James Kirk - An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....
|
|
Xeno Kovah and Corey Kallenberg - No More Hooks: Detection of Code Integrity Attacks
-
www.defcon.org
-
13 years ago
-
eng
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....
|
|
Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....
|
NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID transactions from the perspective of the tag or....
|
|
Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....
|
|
Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....
|
|
Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....
|
|
Amber Lyon and Panel - Anonymous and the Online Fight for Justice
-
www.defcon.org
-
13 years ago
-
eng
Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Studies Marcia Hoffman Senior Staff Attorney, Electronic Frontier Foundation Mercedes Haefer Student, UNLV Jay Leiderman Attorney, Leiderman Devine LLP Gráinne O’Neill Coordinator Anonlg Project, National Lawyers G....
|
OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response through the principle of "train as you fight." We will demonstrate how we have applied OPFOR to build a continuous feedback loop between penetration testing and incident response. In OPFOR 4Ever, th....
|