|
My employer, SheepDogInc , sent me and a colleague of mine to DjangoCon 2011 . It was my first developer conference and I had a blast. Here a few quick points about what the conference has clarified for me. Deploying Django Despite the Django official documentation’s recommendation to use Apache and mod_wsgi, most people seem to deploy Django with nginx and gunicorn. This has been a pleasant surprise to me because I like it but though t....
|
|
My employer, SheepDogInc , sent me and a colleague of mine to DjangoCon 2011 . It was my first developer conference and I had a blast. Here a few quick points about what the conference has clarified for me. Deploying Django Despite the Django official documentation’s recommendation to use Apache and mod_wsgi, most people seem to deploy Django with nginx and gunicorn. This has been a pleasant surprise to me because I like it but though t....
|
|
I’m getting worried about Google. Long one of the champions of the open web alongside Mozilla, the rise of social networking silos and the app economy seem to have scared them. And like any scared organism, they lash out. Many of their plans to make web competitive against native development environments are good, there is indeed much to improve in the stack. But what I’m uneasy with is the unilateral way they go about it, preferrin....
|
|
I’m getting worried about Google. Long one of the champions of the open web alongside Mozilla, the rise of social networking silos and the app economy seem to have scared them. And like any scared organism, they lash out. Many of their plans to make web competitive against native development environments are good, there is indeed much to improve in the stack. But what I’m uneasy with is the unilateral way they go about it, preferrin....
|
|
Well, what was left of my post-Ukrainian childhood, anyway… Website contests Does anyone else remember those website competitions, where you had groups of sites joining teams (usually fantasy-themed) and compete amongst themselves to get the most votes, and then the finalists of those teams would go up against finalists of the other teams until there was one winner left and they got an animated GIF award to put on their page?
|
|
This is awesome for all Vimsters out there. A guy named Michael Pohoreski seems to have had a similar problem to almost every other vim user/beginner out there. He couldn't find a good vim cheat sheet, so he made the mother of all cheat sheets. It's damn ugly, but pretty good:
|
|
This is awesome for all Vimsters out there. A guy named Michael Pohoreski seems to have had a similar problem to almost every other vim user/beginner out there. He couldn't find a good vim cheat sheet, so he made the mother of all cheat sheets. It's damn ugly, but pretty good:
|
|
A while back I applied to Microsoft’s MACH Scheme (graduate scheme) and was lucky enough to get offered a place. Only started on Monday but I’m already loving it. If you’re a student considering applying for graduate jobs I would strongly recommend it . P.s. As I’ve started work and don’t working internet connection at home (yet) I just wanted to quickly apologise for not getting back to people as quickly as I normally would. I will st..
|
|
Brad Woodberg - Network Application Firewalls: Exploits and Defense
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Woodberg/DEFCON-19-Woodberg-Network-Application-Firewalls.pdf In the last few years, a so called whole new generation of firewalls have been released by various vendors, most notably Network Application Firewalling. While this technology has gained a lot of market attention, little is actually known by the general public about how it actually works, what limitations it has, an....
|
|
Brad Woodberg - Network Application Firewalls: Exploits and Defense
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Woodberg/DEFCON-19-Woodberg-Network-Application-Firewalls.pdf In the last few years, a so called whole new generation of firewalls have been released by various vendors, most notably Network Application Firewalling. While this technology has gained a lot of market attention, little is actually known by the general public about how it actually works, what limitations it has, an....
|
|
Brad Woodberg - Network Application Firewalls: Exploits and Defense
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Woodberg/DEFCON-19-Woodberg-Network-Application-Firewalls.pdf In the last few years, a so called whole new generation of firewalls have been released by various vendors, most notably Network Application Firewalling. While this technology has gained a lot of market attention, little is actually known by the general public about how it actually works, what limitations it has, and what ....
|
|
Brad Woodberg - Network Application Firewalls: Exploits and Defense
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Woodberg/DEFCON-19-Woodberg-Network-Application-Firewalls.pdf In the last few years, a so called whole new generation of firewalls have been released by various vendors, most notably Network Application Firewalling. While this technology has gained a lot of market attention, little is actually known by the general public about how it actually works, what limitations it has, an....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zhu/DEFCON-19-Zhu-Phishing-Online-Scams-in-China.pdf Today, Ebay, Paypal and WOW are all popular targets of global phishing. However, phishing in China is different from that in other countries. The Chinese government has already placed a lot of focus on this issue, however, online scams have already gone beyond the traditional scope of phishing. For example, one of the top fi....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zhu/DEFCON-19-Zhu-Phishing-Online-Scams-in-China.pdf Today, Ebay, Paypal and WOW are all popular targets of global phishing. However, phishing in China is different from that in other countries. The Chinese government has already placed a lot of focus on this issue, however, online scams have already gone beyond the traditional scope of phishing. For example, one of the top fi....
|
https://www.defcon.org/defcon-19/dc-19-presentations/Zhu/DEFCON-19-Zhu-Phishing-Online-Scams-in-China.pdf Today, Ebay, Paypal and WOW are all popular targets of global phishing. However, phishing in China is different from that in other countries. The Chinese government has already placed a lot of focus on this issue, however, online scams have already gone beyond the traditional scope of phishing. For example, one of the top five phis....
|
|
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zhu/DEFCON-19-Zhu-Phishing-Online-Scams-in-China.pdf Today, Ebay, Paypal and WOW are all popular targets of global phishing. However, phishing in China is different from that in other countries. The Chinese government has already placed a lot of focus on this issue, however, online scams have already gone beyond the traditional scope of phishing. For example, one of the top fi....
|
|
Zoz, Andrea Bianchi - Vanquishing Voyeurs: Secure Ways To Authenticate Insecurely
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zoz-Bianchi/DEFCON-19-Zoz-Bianchi-Vanquishing-Voyeurs.pdf Observation is one of the principal means of compromise of authentication methods relying on secret information such as PINs and login/password combinations. Attackers can gather this information via observation, either from without by methods such as shoulder surfing and camera-based ATM skimmers, or from within by met....
|
|
Zoz, Andrea Bianchi - Vanquishing Voyeurs: Secure Ways To Authenticate Insecurely
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zoz-Bianchi/DEFCON-19-Zoz-Bianchi-Vanquishing-Voyeurs.pdf Observation is one of the principal means of compromise of authentication methods relying on secret information such as PINs and login/password combinations. Attackers can gather this information via observation, either from without by methods such as shoulder surfing and camera-based ATM skimmers, or from within by met....
|
|
Zoz, Andrea Bianchi - Vanquishing Voyeurs: Secure Ways To Authenticate Insecurely
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Zoz-Bianchi/DEFCON-19-Zoz-Bianchi-Vanquishing-Voyeurs.pdf Observation is one of the principal means of compromise of authentication methods relying on secret information such as PINs and login/password combinations. Attackers can gather this information via observation, either from without by methods such as shoulder surfing and camera-based ATM skimmers, or from within by methods su....
|
|
Zoz, Andrea Bianchi - Vanquishing Voyeurs: Secure Ways To Authenticate Insecurely
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Zoz-Bianchi/DEFCON-19-Zoz-Bianchi-Vanquishing-Voyeurs.pdf Observation is one of the principal means of compromise of authentication methods relying on secret information such as PINs and login/password combinations. Attackers can gather this information via observation, either from without by methods such as shoulder surfing and camera-based ATM skimmers, or from within by met....
|
|
Vulnerability Databases (VDBs) have provided information about security vulnerabilities for over 10 years. This has put VDBs in a unique position to understand and analyze vulnerability trends and changes in the security industry. This panel presentation will examine vulnerability information over the past several years with an emphasis on understanding security researchers, quality of research, vendors, disclosure trends and the value of s....
|
|
Vulnerability Databases (VDBs) have provided information about security vulnerabilities for over 10 years. This has put VDBs in a unique position to understand and analyze vulnerability trends and changes in the security industry. This panel presentation will examine vulnerability information over the past several years with an emphasis on understanding security researchers, quality of research, vendors, disclosure trends and the value of s....
|
|
Jake Kouns, Brian Martin, Steve Christey, Carsten Eiram, Art Manion, Dan Holden, Alex Hutton & Katie Moussouris - Panel: Is it 0-day or 0-care?
-
www.defcon.org
-
14 years ago
-
eng
Vulnerability Databases (VDBs) have provided information about security vulnerabilities for over 10 years. This has put VDBs in a unique position to understand and analyze vulnerability trends and changes in the security industry. This panel presentation will examine vulnerability information over the past several years with an emphasis on understanding security researchers, quality of research, vendors, disclosure trends and the value of s....
|
|
Vulnerability Databases (VDBs) have provided information about security vulnerabilities for over 10 years. This has put VDBs in a unique position to understand and analyze vulnerability trends and changes in the security industry. This panel presentation will examine vulnerability information over the past several years with an emphasis on understanding security researchers, quality of research, vendors, disclosure trends and the value of s....
|
|
Mike Tassey, Rich Perkins - Web Application Analysis With Owasp Hatkit
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Swende-Karlsson/DEFCON-19-Swende-Karlsson-Owasp-Hatkit.pdf The presentation will take a deep dive into two newly released Owasp tools; the Owasp Hatkit Proxy and the Owasp Hatkit Datafiddler. The name Hatkit is an acronym (of sorts) for Http Analysis Toolkit and are tools mainly for people who analyse (hack!) web applications. The tools make extensive use of MongoDB, in particular th....
|
|
Panel - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a res....
|
|
Panel - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a res....
|
|
John J. Strauchs, Tiffany Rad, Teague Newman & Dora The SCADA Explorer - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a result of ....
|
|
Panel - SCADA & PLCs in Correctional Facilities: The Nightmare Before Christmas
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Strauchs-Rad-Newman/DEFCON-19-Strauchs_Rad_Newman-SCADA-in-Prisons.pptx.pdf On Christmas Eve, a call was made from a prison warden: all of the cells on death row popped open. Many prisons and jails use SCADA systems with PLCs to open and close doors. Not sure why or if it would happen, the warden called physical security design engineer, John Strauchs, to investigate. As a res....
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and Twitter ..
|
|
Bruce Sutherland - How To Get Your Message Out When Your Government Turns Off The Internet
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Sutherland/DEFCON-19-Sutherland-How-to-Get-Your-Message-Out.pdf How would you communicate with the world if your government turned off the Internet? Sound far-fetched? It isn't. It already happened in Egypt and Lybia and the US Congress is working on laws that would allow it to do the same. In this talk we'll explore how to get short messages out of the country via Email and T..
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse s..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure and ....
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse ..
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse so they..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Abstrct - When Space Elephants Attack: A DEFCON Challenge for Database Geeks
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Absrtct/DEFCON-19-Abstrct-The-Schemaverse.pdf The Schemaverse is a vast universe found purely within a PostgreSQL database. Control your fleet of ships manually with SQL commands or write AI in PL/pgSQL so they control themselves while you sit back and enjoy the con. This presentation will help my fellow database geeks to understand the game play mechanics used in The Schemaverse s..
|
|
General Keith B. Alexander - Shared Values, Shared Responsibility
-
www.defcon.org
-
14 years ago
-
eng
Shared Values, Shared Responsibility General Keith B. Alexander Commander, US Cyber Command (USCYBERCOM) and Director, National Security AgenCy/Chief, Central Security Service (NSA/CSS) We as a global society are extremely vulnerable and at risk for a catastrophic cyber event. Global society needs the best and brightest to help secure our most valued resources in cyberspace: our intellectual property, our critical infrastructure an....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attac....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Dust: Your Feed RSS Belongs To You! Avoid Censorship!
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-DUST.pdf Law around the world is trying to control what is published on the Internet. After wikileaks case and HBGary ownage everybody could see how there are many controls that can be used to close a website, a domain name and to cut the communication between the source and the audience. What happened if someone wants to close your blog?....
|
|
Chema Alonso, Juan Garrido "Silverhack" - Bosses love Excel, Hackers too.
-
www.defcon.org
-
14 years ago
-
eng
https://www.defcon.org/images/defcon-19/dc-19-presentations/Alonso-Garrido/DEFCON-19-Alonso-Garrido-Excel.pdf Remote applications published in companies are around us in the cloud. In this talk we are going to add ICA and Terminal Server Apps to fingerprinting process, automating data analysis using FOCA. It will allow attacker to fingerprinting internal software, internal networks and combine the info in PTR Scanning, evil-grade attac....
|