|
Christopher Soghoian - Your ISP and the Government: Best Friends Forever
-
www.defcon.org
-
15 years ago
-
eng
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law enforcement and intelligence agencies. Worse, firms like Google and Microsoft specifically log data in order to assist the government, while AT&T and Verizon are paid $1.8 million per year in order to provide real time access to customer communica....
|
|
Christopher Soghoian - Your ISP and the Government: Best Friends Forever
-
www.defcon.org
-
15 years ago
-
eng
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law enforcement and intelligence agencies. Worse, firms like Google and Microsoft specifically log data in order to assist the government, while AT&T and Verizon are paid $1.8 million per year in order to provide real time access to customer communica....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumvent....
|
|
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized queries, XSRF tokens, X.509 certificates, and escapes in all their glorious forms? I will tell you: It is because these tools are not very good. And they are not very good, because their quality simply has not mattered. Security demands, devs....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|
|
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information being generated and gathered all the time. While much of this data goes by unnoticed or ignored it contains fascinating insight into the behavior and trends that we see throughout society. The trick is being able to identify and isolate the u....
|
|
The Dark Tangent & Joe Grand - Welcome and Making the DEF CON 18 Badge
-
www.defcon.org
-
15 years ago
-
eng
For the fifth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? If you're in this talk and not standing in a long line to get your badge, then the answer is "Yes!" Join Kingpin as he guides you through the entir..
|
|
Hardware hacking is cool, but it can be daunting to software guys. Microcontrollers mix hardware and software basically allowing software guys to do hardware in software. Lately several products have emerged that make it even easier for software guys to get hardware up and working. Arduinos are relatively cheap, open source, all-in-one prototyping boards with a strong community behind them. All you need is a USB cable and the Ardu....
|
|
The Dark Tangent & Joe Grand - Welcome and Making the DEF CON 18 Badge
-
www.defcon.org
-
15 years ago
-
eng
For the fifth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? If you're in this talk and not standing in a long line to get your badge, then the answer is "Yes!" Join Kingpin as he guides you through the entir..
|
|
Hardware hacking is cool, but it can be daunting to software guys. Microcontrollers mix hardware and software basically allowing software guys to do hardware in software. Lately several products have emerged that make it even easier for software guys to get hardware up and working. Arduinos are relatively cheap, open source, all-in-one prototyping boards with a strong community behind them. All you need is a USB cable and the Ardu....
|
|
The Dark Tangent & Joe Grand - Welcome and Making the DEF CON 18 Badge
-
www.defcon.org
-
15 years ago
-
eng
For the fifth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? If you're in this talk and not standing in a long line to get your badge, then the answer is "Yes!" Join Kingpin as he guides you through the entir..
|
|
Hardware hacking is cool, but it can be daunting to software guys. Microcontrollers mix hardware and software basically allowing software guys to do hardware in software. Lately several products have emerged that make it even easier for software guys to get hardware up and working. Arduinos are relatively cheap, open source, all-in-one prototyping boards with a strong community behind them. All you need is a USB cable and the Ardu....
|
|
David "VideoMan" M. N. Bryan & Michael Anderson - Cloud Computing, a Weapon of Mass Destruction?
-
www.defcon.org
-
15 years ago
-
eng
Using cloud computing to attack systems allows for the testing of a company's incident response and recovery program. We have been using the cloud computing environment to test real world scenarios for different types of attacks, such as Distributed Denial of Service, Flooding, and Packet Fragmentation. The presentation will review some of the common attack types, what they are, and how they can be used to disrupt service. I will also revie....
|
|
David "VideoMan" M. N. Bryan & Michael Anderson - Cloud Computing, a Weapon of Mass Destruction?
-
www.defcon.org
-
15 years ago
-
eng
Using cloud computing to attack systems allows for the testing of a company's incident response and recovery program. We have been using the cloud computing environment to test real world scenarios for different types of attacks, such as Distributed Denial of Service, Flooding, and Packet Fragmentation. The presentation will review some of the common attack types, what they are, and how they can be used to disrupt service. I will also revie....
|
|
David "VideoMan" M. N. Bryan & Michael Anderson - Cloud Computing, a Weapon of Mass Destruction?
-
www.defcon.org
-
15 years ago
-
eng
Using cloud computing to attack systems allows for the testing of a company's incident response and recovery program. We have been using the cloud computing environment to test real world scenarios for different types of attacks, such as Distributed Denial of Service, Flooding, and Packet Fragmentation. The presentation will review some of the common attack types, what they are, and how they can be used to disrupt service. I will also revie....
|
|
David C. Smith & Samuel Petreski - A New Approach to Forensic Methodology - !!BUSTED!! case studies
-
www.defcon.org
-
15 years ago
-
eng
Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case. The analysts are then measured based on the total....
|
|
Powershell is as close to a programming language we are going to get through a command line interface on Windows. The ability to perform almost any task we want through Windows is a huge benefit for systems administrators... and hackers. During this presentation we'll be releasing a new attack vector through Powershell that allows you to deliver whatever payload you want to through Powershell in both a bind and reverse type scenario and dro....
|
|
David C. Smith & Samuel Petreski - A New Approach to Forensic Methodology - !!BUSTED!! case studies
-
www.defcon.org
-
15 years ago
-
eng
Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case. The analysts are then measured based on the total....
|
|
Powershell is as close to a programming language we are going to get through a command line interface on Windows. The ability to perform almost any task we want through Windows is a huge benefit for systems administrators... and hackers. During this presentation we'll be releasing a new attack vector through Powershell that allows you to deliver whatever payload you want to through Powershell in both a bind and reverse type scenario and dro....
|
|
David C. Smith & Samuel Petreski - A New Approach to Forensic Methodology - !!BUSTED!! case studies
-
www.defcon.org
-
15 years ago
-
eng
Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case. The analysts are then measured based on the total....
|
|
Powershell is as close to a programming language we are going to get through a command line interface on Windows. The ability to perform almost any task we want through Windows is a huge benefit for systems administrators... and hackers. During this presentation we'll be releasing a new attack vector through Powershell that allows you to deliver whatever payload you want to through Powershell in both a bind and reverse type scenario and dro....
|
|
David Maynor & Paul Judge, PhD - Searching for Malware: A Review of Attackers’ Use of Search Engines to Lure Victims
-
www.defcon.org
-
15 years ago
-
eng
For many people, the first page they visit online is a search engine; in fact, in the US alone more than 14 billion searches per month happen on Google, Yahoo! and Bing. These searches are then siphoned into thousands of popular search terms that are ripe for attackers to exploit. Attackers understand the number of eyeballs and browsers that are at stake and have targeted their attacks against popular search engine results in order to reach....
|
|
David Maynor & Paul Judge, PhD - Searching for Malware: A Review of Attackers’ Use of Search Engines to Lure Victims
-
www.defcon.org
-
15 years ago
-
eng
For many people, the first page they visit online is a search engine; in fact, in the US alone more than 14 billion searches per month happen on Google, Yahoo! and Bing. These searches are then siphoned into thousands of popular search terms that are ripe for attackers to exploit. Attackers understand the number of eyeballs and browsers that are at stake and have targeted their attacks against popular search engine results in order to reach....
|
|
David Maynor & Paul Judge, PhD - Searching for Malware: A Review of Attackers’ Use of Search Engines to Lure Victims
-
www.defcon.org
-
15 years ago
-
eng
For many people, the first page they visit online is a search engine; in fact, in the US alone more than 14 billion searches per month happen on Google, Yahoo! and Bing. These searches are then siphoned into thousands of popular search terms that are ripe for attackers to exploit. Attackers understand the number of eyeballs and browsers that are at stake and have targeted their attacks against popular search engine results in order to reach....
|
|
For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies are hard at work building surveillance interfaces into their networks. Do these lawful intercept interfaces create unnecessary security risks? This talk will review published architectures for lawful intercept and explain how a number of di....
|
|
In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks against the living around them. Fortunately, the living had their own devices, and were able to fight off the zombies... but more threatening enemies entered the fray. This is the story about the QuahogCon 2010 badge and the embedded Zombie I....
|
|
For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies are hard at work building surveillance interfaces into their networks. Do these lawful intercept interfaces create unnecessary security risks? This talk will review published architectures for lawful intercept and explain how a number of di....
|
|
In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks against the living around them. Fortunately, the living had their own devices, and were able to fight off the zombies... but more threatening enemies entered the fray. This is the story about the QuahogCon 2010 badge and the embedded Zombie I....
|
|
For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies are hard at work building surveillance interfaces into their networks. Do these lawful intercept interfaces create unnecessary security risks? This talk will review published architectures for lawful intercept and explain how a number of di....
|
|
In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks against the living around them. Fortunately, the living had their own devices, and were able to fight off the zombies... but more threatening enemies entered the fray. This is the story about the QuahogCon 2010 badge and the embedded Zombie I....
|
|
There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..
|
|
There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..
|
|
There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..
|
|
Toool - The Search for Perfect Handcuffs... and the Perfect Handcuff Key
-
www.defcon.org
-
15 years ago
-
eng
Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....
|
|
Dondi West - An Examination of the Adequacy of the Laws Related to Cyber Warfare
-
www.defcon.org
-
15 years ago
-
eng
This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....
|
|
Toool - The Search for Perfect Handcuffs... and the Perfect Handcuff Key
-
www.defcon.org
-
15 years ago
-
eng
Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....
|
|
Dondi West - An Examination of the Adequacy of the Laws Related to Cyber Warfare
-
www.defcon.org
-
15 years ago
-
eng
This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....
|
|
Toool - The Search for Perfect Handcuffs... and the Perfect Handcuff Key
-
www.defcon.org
-
15 years ago
-
eng
Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....
|
|
Dondi West - An Examination of the Adequacy of the Laws Related to Cyber Warfare
-
www.defcon.org
-
15 years ago
-
eng
This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....
|