|
The different technologies today for providing IP-access over the air to handheld devices all pose some interesting questions about traditional securitywork. How to firewall? What is the physical differences of being on the "inside" versus the "outside" of the firewall? How to implement prudent securitymeasures if there is no security on the physical layer? Today, we can conclude that most base-stations used for Radio LAN:s, regardless of t....
|
|
Mark Grimes - TCP/IP Intelligent Agents: The Future of Electronic Warfare and Defense
-
defcon.org
-
16 years ago
-
eng
The study of Artificial Intelligence bring many treasures to the development of both offensive and defensive network tools. Code can be designed to make "intelligent" decisions based on a presented data sample. When rules are explicitly laid out by RFC to indicate proper connection handling, these rules can be mapped and recalled. This would allow for an automated handling of network traffic with decision making enforced on next-packet in....
|
|
Mark Grimes - TCP/IP Intelligent Agents: The Future of Electronic Warfare and Defense
-
defcon.org
-
16 years ago
-
eng
The study of Artificial Intelligence bring many treasures to the development of both offensive and defensive network tools. Code can be designed to make "intelligent" decisions based on a presented data sample. When rules are explicitly laid out by RFC to indicate proper connection handling, these rules can be mapped and recalled. This would allow for an automated handling of network traffic with decision making enforced on next-packet in....
|
|
It is now an accepted fact that computer hackers, crackers, hacktivists, virus writers, and other politically-aware individuals in the computer underground are 'taking matters into their own hands.' Whether through website defacementsor full-scale denial-of-service attacks, non-governmental, non-aligned individuals and groups are conducting what the military refers to as 'information operations' of increasing sophistication. What is c....
|
|
It is now an accepted fact that computer hackers, crackers, hacktivists, virus writers, and other politically-aware individuals in the computer underground are 'taking matters into their own hands.' Whether through website defacementsor full-scale denial-of-service attacks, non-governmental, non-aligned individuals and groups are conducting what the military refers to as 'information operations' of increasing sophistication. What is c....
|
|
The old addage holds there is an inverse relationship between usability and security. The more user-friendly the system, the less secure it is. However, recent user heuristics research may lend insight into how to design more usable, more secure operating system interfaces--independent of the underlying OS architecture, AND the gullibility of the user. By highlighting the graphical and subtexual cues recently highlighted in popular OS....
|
|
The old addage holds there is an inverse relationship between usability and security. The more user-friendly the system, the less secure it is. However, recent user heuristics research may lend insight into how to design more usable, more secure operating system interfaces--independent of the underlying OS architecture, AND the gullibility of the user. By highlighting the graphical and subtexual cues recently highlighted in popular OS....
|
|
During my research with the “ICMP Usage In Scanning” project, I have discovered some new active and passive operating system fingerprinting methods using the ICMP protocol. Methods that are simple, and efficient. The active operating system fingerprinting methods were not correlated into a certain logic. A logic that would allow us to have the ability to use any available method in order to, wisely, actively fingerprint an operating s....
|
|
During my research with the "ICMP Usage In Scanning" project, I have discovered some new active and passive operating system fingerprinting methods using the ICMP protocol. Methods that are simple, and efficient. The active operating system fingerprinting methods were not correlated into a certain logic. A logic that would allow us to have the ability to use any available method in order to, wisely, actively fingerprint an operating s....
|
|
This is the release of KIS. KIS is a self contained binary that when executed on a system installs itself so that it will be loaded on reboot and loads a kernel module. This LKM hides itself, all of its subprocesses or desired processes, all of their files, directories, and network connections automatically. The presentation will consist of demonstrating how to setup and use KIS as well as explain some of the basic design concepts. O..
|
|
This is the release of KIS. KIS is a self contained binary that when executed on a system installs itself so that it will be loaded on reboot and loads a kernel module. This LKM hides itself, all of its subprocesses or desired processes, all of their files, directories, and network connections automatically. The presentation will consist of demonstrating how to setup and use KIS as well as explain some of the basic design concepts. O..
|
|
Mr. Shipley will discuss his latest research concerning open WLANs in the corporate and home environment. Early results will be presented along with maps illustrating the current threats showing that the current security models in 802.11 networking have set the state of network security back a decade. Mr. Shipley is one of the few individuals who is well known and highly respected in the professional world as well as the underground /....
|
|
Mr. Shipley will discuss his latest research concerning open WLANs in the corporate and home environment. Early results will be presented along with maps illustrating the current threats showing that the current security models in 802.11 networking have set the state of network security back a decade. Mr. Shipley is one of the few individuals who is well known and highly respected in the professional world as well as the underground /....
|
|
Phil King - 8 Bits and 8 Pins: More Fun With Micro controller Hacking
-
defcon.org
-
16 years ago
-
eng
Microcontrollers" are microprocessors with additional peripherals, I/O controls, and memory all built into one chip. Last year, Phil introduced the wonderful world of 8-bit micro controllers and showed how to set up your own project development lab. This year he looks at more fun, cute, and devious electronic devices you can build, this time focusing on micro controllers with only 8 pins. What can you do with 2K of code spaces and only a ....
|
|
Phil King - 8 Bits and 8 Pins: More Fun With Micro controller Hacking
-
defcon.org
-
16 years ago
-
eng
Microcontrollers" are microprocessors with additional peripherals, I/O controls, and memory all built into one chip. Last year, Phil introduced the wonderful world of 8-bit micro controllers and showed how to set up your own project development lab. This year he looks at more fun, cute, and devious electronic devices you can build, this time focusing on micro controllers with only 8 pins. What can you do with 2K of code spaces and only a ....
|
|
Raven Alder - A Perl script that tracks Denial of Service attacks across Cisco backbones.
-
defcon.org
-
16 years ago
-
eng
Denial of Service attacks are well known in the security field, but in recent years distributed Denial of Service attacks have become more of a worry and a priority to ISPs. Recognizing when a DDoS attack is crossing your network is important, and being able to shut it down at your network's edge is even more so. But due to the increasing ease of spoofing the source IPs of a DDoS attack, correctly finding where the traffic is entering you....
|
|
Richard Thieme - Hacking in a Context of Pan-global Culture, the Wetware / dryware Interface, and Going to Europa
-
defcon.org
-
16 years ago
-
eng
When Richard Thieme spoke at DefCon 4, he said hacking was practice for trans-planetary life in the 21st century. Well, guess what? It was. But a changing context has also changed what hacking looks like. Context is content, and what was hacking at MIT on a PDP-6 just doesn't cut it any more. The essence of hacking is the same, but the game is played differently. When space war involves holographic image projection, cloaking devices, multis....
|
|
Raven Alder - A Perl script that tracks Denial of Service attacks across Cisco backbones.
-
defcon.org
-
16 years ago
-
eng
Denial of Service attacks are well known in the security field, but in recent years distributed Denial of Service attacks have become more of a worry and a priority to ISPs. Recognizing when a DDoS attack is crossing your network is important, and being able to shut it down at your network's edge is even more so. But due to the increasing ease of spoofing the source IPs of a DDoS attack, correctly finding where the traffic is entering you....
|
|
Richard Thieme - Hacking in a Context of Pan-global Culture, the Wetware / dryware Interface, and Going to Europa
-
defcon.org
-
16 years ago
-
eng
When Richard Thieme spoke at DefCon 4, he said hacking was practice for trans-planetary life in the 21st century. Well, guess what? It was. But a changing context has also changed what hacking looks like. Context is content, and what was hacking at MIT on a PDP-6 just doesn't cut it any more. The essence of hacking is the same, but the game is played differently. When space war involves holographic image projection, cloaking devices, multis....
|
|
This session will detail a methodology by which security professionals may independently examine the security of a VPN. We will cover basic concepts of key exchange and management, leading into a description of good and bad ways by which the two ends of a VPN connection arrive at the necessary shared secret. We will discuss common mistakes such as improper random seeding or key exchange, and step through a checklist of things to check. F..
|
|
This session will detail a methodology by which security professionals may independently examine the security of a VPN. We will cover basic concepts of key exchange and management, leading into a description of good and bad ways by which the two ends of a VPN connection arrive at the necessary shared secret. We will discuss common mistakes such as improper random seeding or key exchange, and step through a checklist of things to check. F..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
Robert Grill & Michael Cohen - Windows NT and Novell Host Based Intrusion Detection Using Native Logging and 3rd Party Log Reporting Tools
-
defcon.org
-
16 years ago
-
eng
Auditing is defined for this presentation as the process of examining operating system (OS) audit logs to assure information stored on computers is properly protected, and meets corporate security policies. This presentation will cover the Novell NetWare 4.11 (NW) and Windows NT 4.0 (NT) operating systems. NW is capable of auditing Novell Directory Services (NDS) and file system actions, and NT for domain and file systems actions, perfo....
|
|
Robert Grill & Michael Cohen - Windows NT and Novell Host Based Intrusion Detection Using Native Logging and 3rd Party Log Reporting Tools
-
defcon.org
-
16 years ago
-
eng
Auditing is defined for this presentation as the process of examining operating system (OS) audit logs to assure information stored on computers is properly protected, and meets corporate security policies. This presentation will cover the Novell NetWare 4.11 (NW) and Windows NT 4.0 (NT) operating systems. NW is capable of auditing Novell Directory Services (NDS) and file system actions, and NT for domain and file systems actions, perfo....
|
|
We will begin with basic IOS Commands to secure a router, looking at unneed services and turning off seldom used protocols. From there we will look at configurations for defeating basic attacks against your network, including DDos,SMURF and other nasty things you can do to netowrks. Next we will look at some Simply Access list and nifty tricks you can do with them! I will also discuss the basics of Encryption, RADIUS and other security me..
|
|
We will begin with basic IOS Commands to secure a router, looking at unneed services and turning off seldom used protocols. From there we will look at configurations for defeating basic attacks against your network, including DDos,SMURF and other nasty things you can do to netowrks. Next we will look at some Simply Access list and nifty tricks you can do with them! I will also discuss the basics of Encryption, RADIUS and other security me..
|
|
Sharad - Security & Privacy are Critically important issues in Todays Digitally Connected Age
-
defcon.org
-
16 years ago
-
eng
The typical netizen is blissfully unaware of the dangers that lurk each time he or she gets connected. Others consider security to be a "black art", too complex to understand - and therefore studiously avoid anything to do with it. This session serves as an introduction to the dangers that abound in today's networked existence. Besides presenting an overview of various attacks, the talk tries to demystify them by explaining the "how it....
|
|
Sharad - Security & Privacy are Critically important issues in Todays Digitally Connected Age
-
defcon.org
-
16 years ago
-
eng
The typical netizen is blissfully unaware of the dangers that lurk each time he or she gets connected. Others consider security to be a "black art", too complex to understand - and therefore studiously avoid anything to do with it. This session serves as an introduction to the dangers that abound in today's networked existence. Besides presenting an overview of various attacks, the talk tries to demystify them by explaining the "how it....
|
|
Shatter - FAQ The Newbies: Information for people new to security, hacking or Defcon
-
defcon.org
-
16 years ago
-
eng
ETTIQUITE: How to approch people, talk with people, introduce yourself and how not to be a lamer. Example will include real life anecdotes, stories from past cons, and even things that happened the night before. PHILOSOPHY: Why are you here, and what are you doing? What is your motivation to be here? Why do you hack? Also included in this section is the concept of ethics: How your actions effect yourself, others, and the net ....
|
|
Simple Nomad - Widdershins: De-evolution and the Politics of Technology
-
defcon.org
-
16 years ago
-
eng
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
Shatter - FAQ The Newbies: Information for people new to security, hacking or Defcon
-
defcon.org
-
16 years ago
-
eng
ETTIQUITE: How to approch people, talk with people, introduce yourself and how not to be a lamer. Example will include real life anecdotes, stories from past cons, and even things that happened the night before. PHILOSOPHY: Why are you here, and what are you doing? What is your motivation to be here? Why do you hack? Also included in this section is the concept of ethics: How your actions effect yourself, others, and the net ....
|
|
Simple Nomad - Widdershins: De-evolution and the Politics of Technology
-
defcon.org
-
16 years ago
-
eng
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
TechnoDragon - Hardware mods, how to look for them, what telltale signs to look for, how to identify what hardware most likely can be modified, etc
-
defcon.org
-
16 years ago
-
eng
Hardware mods. Have you ever wondered what special features can be enabled is your hardware, or even crippled for security reasons? Well, I will cover theory, fact and many designs covering identification and activation of hidden features wether they be hardware or software. Topics will include: · Identification of places to perform mods in hardware. · How to manipulate mods and features and settings to enable mods. · How to ..
|
|
TechnoDragon - Hardware mods, how to look for them, what telltale signs to look for, how to identify what hardware most likely can be modified, etc
-
defcon.org
-
16 years ago
-
eng
Hardware mods. Have you ever wondered what special features can be enabled is your hardware, or even crippled for security reasons? Well, I will cover theory, fact and many designs covering identification and activation of hidden features wether they be hardware or software. Topics will include: · Identification of places to perform mods in hardware. · How to manipulate mods and features and settings to enable mods. · How to ..
|
|
Thomas J. Munn - Using Open BSD, snort, Linux, and a few other tricks to set up a transparent, ACTIVE Ids
-
defcon.org
-
16 years ago
-
eng
Basically I will cover: How to set up Snort Sensor in Openbsd. - How to use Perl & Rules to actively adapt rules to attacks, while keeping yourself from being "DOSSED" - How to use ACID to make logs more easily accessible, and analyzed, - How to Use database portion to look at historical attack trends and react appropriately. - How to set up "safe" management segment on your network that is both accessible to you, but hard for "them" to get..
|
|
Thomas J. Munn - Using Open BSD, snort, Linux, and a few other tricks to set up a transparent, ACTIVE Ids
-
defcon.org
-
16 years ago
-
eng
Basically I will cover: How to set up Snort Sensor in Openbsd. - How to use Perl & Rules to actively adapt rules to attacks, while keeping yourself from being "DOSSED" - How to use ACID to make logs more easily accessible, and analyzed, - How to Use database portion to look at historical attack trends and react appropriately. - How to set up "safe" management segment on your network that is both accessible to you, but hard for "them" to get..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..
|
|
For the past three years, Dr. Tafoya has been Professor of Criminal Justice at Governors State University. Previously he was Director of Research, Office of International Criminal Justice, University of Illinois at Chicago. He is a retired Special Agent of the Federal Bureau of Investigation. For 12 months (July 1989 – July 1990), he served as Congressional Research Fellow for the 101st Congress in Washington, DC. There he conducted re....
|
|
For the past three years, Dr. Tafoya has been Professor of Criminal Justice at Governors State University. Previously he was Director of Research, Office of International Criminal Justice, University of Illinois at Chicago. He is a retired Special Agent of the Federal Bureau of Investigation. For 12 months (July 1989 – July 1990), he served as Congressional Research Fellow for the 101st Congress in Washington, DC. There he conducted re....
|
|
A quick personal post to break the silence here! I’m currently very interested in hearing about any UK or EU-based network engineering or architecture opportunities that are out there, especially in SP networks that run MPLS with TE. If anyone has some such opportunity, or knows of something that they think might suit me – please drop me a mail to rjs@rob.sh for a copy of my CV. An outline of my CV is available on LinkedIn . ..
|