|
Anyone who’s looked into Oracle X$ tables, knows that their names are really complicated and quite unreadable (and non-pronouncable), such X$KZSRT, X$KCPXPL, X$KQFSZ and so on. A few years ago at some conference someone came up with a thought that the reason why Oracle has so unreadable names for its X$ tables is that the leading edge database source code was actually stolen in the 80’s from a Soviet Union intelligence agency.
|
|
Anyone who’s looked into Oracle X$ tables, knows that their names are really complicated and quite unreadable (and non-pronouncable), such X$KZSRT, X$KCPXPL, X$KQFSZ and so on. A few years ago at some conference someone came up with a thought that the reason why Oracle has so unreadable names for its X$ tables is that the leading edge database source code was actually stolen in the 80’s from a Soviet Union intelligence agency.
|
|
When debugging, I often found that NSLog is really boring, here is an attempt to make it nicer: ` NSLog(@"mycar: %@",myCar); NSLog(@" I'M HERE "); ` NSLog doesn’t tell you where the call was made (which file or which method), so you end with a lot of: 2009-03-11 22:30:53.789 ObjCTest[1565:10b] mycar: Porsche 2009-03-11 22:30:53.791 ObjCTest[1565:10b] I’M HERE A better NSLog could tell us: 2009-03-11 22:32:25.823 ObjCTest[1581:10b] Car.m:32 ..
|
|
Today and tomorrow I am at an Ask Tom Live Seminar in Prague . Tom Kyte works for Oracle and has written many books on Oracle. For me he’s a bit of a “star”, so when I heard he was talking in Europe, I had to come. (But is that wrong? Normal people are in to stars like Robbie Williams surely, not Oracle experts.) Wow there is so much I don’t know about Oracle evidently. I mean the solutions that he is presenting concerning Oracle 11g, ar..
|
|
Yanko Design's You-SB concept : Jerry's real prosthetic USB finger storage : The story behind this is that Jerry had a motorcycle accident last May and lost a finger. When the doctor working on the artificial finger heard he is a hacker , the immediate suggestion was to embed a USB "finger drive" to the design. Now he carries a Billix Linux distribution and the Freddy Got Fingered movie as part of his hand. Yan..
|
|
Yanko Design's You-SB concept : Jerry's real prosthetic USB finger storage : The story behind this is that Jerry had a motorcycle accident last May and lost a finger. When the doctor working on the artificial finger heard he is a hacker , the immediate suggestion was to embed a USB "finger drive" to the design. Now he carries a Billix Linux distribution and the Freddy Got Fingered movie as part of his hand. Yan..
|
|
I haven’t blogged for a while. This is partly because my daughter and I have been enjoying some major events in Toronto (Ontario Science Centre, ROM, shopping, more shopping, etc.), and not much has happened in the Geek world aside from the new Apple hardware updates and Firefox achieving 100% market share in Antarctica. However, the main reason I haven’t blogged is that I have been engrossed with reading the 10th Anniversary book from ..
|
|
I haven’t blogged for a while. This is partly because my daughter and I have been enjoying some major events in Toronto (Ontario Science Centre, ROM, shopping, more shopping, etc.), and not much has happened in the Geek world aside from the new Apple hardware updates and Firefox achieving 100% market share in Antarctica. However, the main reason I haven’t blogged is that I have been engrossed with reading the 10th Anniversary book from ..
|
|
I thought to post about another new interest of mine, TimestTen, as I’ve worked with it in past and I have become a fan of it, especially after Oracle bought the company. Oracle has announced that TimesTen in-memory database will support PL/SQL in the upcoming release. That’s in 11gR2, where TimesTen is named the “in-memory database cache”. I’m happy to see the deep level of integration Oracle is doing with it. It looks like both classi..
|
|
I thought to post about another new interest of mine, TimestTen, as I’ve worked with it in past and I have become a fan of it, especially after Oracle bought the company. Oracle has announced that TimesTen in-memory database will support PL/SQL in the upcoming release. That’s in 11gR2, where TimesTen is named the “in-memory database cache”. I’m happy to see the deep level of integration Oracle is doing with it. It looks like both classi..
|
|
If you read my previous blog on the economy, you’ll see how I explain recessions as part of the inherent flaw of capitalism. As a recap, it is essentially because business people need to earn more than their customers, and their customers need to make more than the business people. This concept would make one wonder how capitalism works at all.
|
|
If the only requirement for you to become a Computer Forensic person is to be a Private Investigator, why would you ever take a certification again? You would never need to be a CCE (computer certified examiner), nor any other certification of any kind. You would be one of the only people in your area that could legally do the job and why spend a single dime you don't have to? These new laws will destroy certifications and qualifications as....
|
|
If the only requirement for you to become a Computer Forensic person is to be a Private Investigator, why would you ever take a certification again? You would never need to be a CCE (computer certified examiner), nor any other certification of any kind. You would be one of the only people in your area that could legally do the job and why spend a single dime you don't have to? These new laws will destroy certifications and qualifications as....
|
|
Chema Alonso & Jose Parada: Time-Based Blind SQL Injection using heavy queries: A practical approach for MS SQL Server, MS Access, Oracle and MySQL databases and Marathon Tool
-
www.defcon.org
-
17 years ago
-
eng
This presentation describes how attackers could take advantage of SQL Injection vulnerabilities using time-based blind SQL injection. The goal is to stress the importance of establishing secure development best practices for Web applications and not only to entrust the site security to the perimeter defenses. This article shows exploitation examples for some versions of Microsoft SQL Server, Oracle DB Engine,MySQL and Microsoft Access datab....
|
|
Chema Alonso & Jose Parada: Time-Based Blind SQL Injection using heavy queries: A practical approach for MS SQL Server, MS Access, Oracle and MySQL databases and Marathon Tool
-
www.defcon.org
-
17 years ago
-
eng
This presentation describes how attackers could take advantage of SQL Injection vulnerabilities using time-based blind SQL injection. The goal is to stress the importance of establishing secure development best practices for Web applications and not only to entrust the site security to the perimeter defenses. This article shows exploitation examples for some versions of Microsoft SQL Server, Oracle DB Engine,MySQL and Microsoft Access datab....
|
|
The market share for Apple devices has grown considerably over the past few years, but most reverse engineering topics still focus on Microsoft platforms. This talk will outline what is necessary to begin reversing software on OS X. This will include a rundown of the tools available to an apple based researcher, how Objective-C works and what it looks like in a binary, the basics of the Mach-O file format including the undocumented _OBJC se..
|
|
The market share for Apple devices has grown considerably over the past few years, but most reverse engineering topics still focus on Microsoft platforms. This talk will outline what is necessary to begin reversing software on OS X. This will include a rundown of the tools available to an apple based researcher, how Objective-C works and what it looks like in a binary, the basics of the Mach-O file format including the undocumented _OBJC se..
|
|
Over the last several years, we've seen a decrease in effectiveness of "classical" security tools. The nature of the present day attacks is very different from what the security community has been used to in the past. Rather than wide-spread worms and viruses that cause general havoc, attackers are directly targeting their victims in order to achieve monetary or military gain. These attacks are blowing right past firewalls and anti-virus an....
|
|
Over the last several years, we've seen a decrease in effectiveness of "classical" security tools. The nature of the present day attacks is very different from what the security community has been used to in the past. Rather than wide-spread worms and viruses that cause general havoc, attackers are directly targeting their victims in order to achieve monetary or military gain. These attacks are blowing right past firewalls and anti-virus an....
|
|
Brian K. Edwards & Silvio J. Flaim: Measuring and Integrating the Shadow Economy: A Sector-Specific Approach
-
www.defcon.org
-
17 years ago
-
eng
Much literature has addressed the issue of the relative sizes of shadow economies in different countries. What is largely missing from this discussion is a more structured discussion on how to incorporate estimates of shadow economic activity into the national income accounting framework and a discussion of how the shadow components of specific industries can be analyzed in either an input-output or macroeconomic framework. After a brief di....
|
|
Brian K. Edwards & Silvio J. Flaim: Measuring and Integrating the Shadow Economy: A Sector-Specific Approach
-
www.defcon.org
-
17 years ago
-
eng
Much literature has addressed the issue of the relative sizes of shadow economies in different countries. What is largely missing from this discussion is a more structured discussion on how to incorporate estimates of shadow economic activity into the national income accounting framework and a discussion of how the shadow components of specific industries can be analyzed in either an input-output or macroeconomic framework. After a brief di....
|
|
Brenno J.S.A.A.F. de Winter:The Anatomy of a Subway Hack: Discussion
-
www.defcon.org
-
17 years ago
-
eng
This talk was given by Brenno de Winter in place of the much talked about canceled talk : The Anatomy of a Subway Hack:Breaking Crypto RFID's and Magstripes of Ticketing Systems by the original authors: Zack Anderson Student, MIT RJ Ryan Student, MIT Alessandro Chiesa Student, MIT In this talk we go over weaknesses in common subway fare collection systems. We focus on the Boston T subway, and show how we reverse en....
|
|
Brenno J.S.A.A.F. de Winter:The Anatomy of a Subway Hack: Discussion
-
www.defcon.org
-
17 years ago
-
eng
This talk was given by Brenno de Winter in place of the much talked about canceled talk : The Anatomy of a Subway Hack:Breaking Crypto RFID's and Magstripes of Ticketing Systems by the original authors: Zack Anderson Student, MIT RJ Ryan Student, MIT Alessandro Chiesa Student, MIT In this talk we go over weaknesses in common subway fare collection systems. We focus on the Boston T subway, and show how we reverse en....
|
|
Brenno J.S.A.A.F. de Winter: Hacking Data Retention: Small Sister your digital privacy self defense.
-
www.defcon.org
-
17 years ago
-
eng
Over the last couple of years a range of privacy threats have been in occurring. Europe is starting to look like the playing field of what is to come to the US: Storage of all e-mail traffic, online presence, phone calls, actual traveling throughout nations and filtering of content. Fortunately a closer look at the measures shows that it is never smart to overestimate the abilities European governments have and digital self defense is possi....
|
|
Brenno J.S.A.A.F. de Winter: Hacking Data Retention: Small Sister your digital privacy self defense.
-
www.defcon.org
-
17 years ago
-
eng
Over the last couple of years a range of privacy threats have been in occurring. Europe is starting to look like the playing field of what is to come to the US: Storage of all e-mail traffic, online presence, phone calls, actual traveling throughout nations and filtering of content. Fortunately a closer look at the measures shows that it is never smart to overestimate the abilities European governments have and digital self defense is possi....
|
|
Blake Self, Durandal & Bitemytaco: Free Anonymous Internet Using Modified Cable Modems
-
www.defcon.org
-
17 years ago
-
eng
Using various modifications and techniques - it is possible to gain free and anonymous cable modem internet access. This talk will analyze and discuss the tools, techniques, and technology behind both hacking cable modems and attempting to catch the users who are hacking cable modems. Previously confidential information gained from a senior network technician at Time Warner will be disclosed in this speech. We will also talk about how these....
|
|
Blake Self, Durandal & Bitemytaco: Free Anonymous Internet Using Modified Cable Modems
-
www.defcon.org
-
17 years ago
-
eng
Using various modifications and techniques - it is possible to gain free and anonymous cable modem internet access. This talk will analyze and discuss the tools, techniques, and technology behind both hacking cable modems and attempting to catch the users who are hacking cable modems. Previously confidential information gained from a senior network technician at Time Warner will be disclosed in this speech. We will also talk about how these....
|
|
With webapp protection now mandated by the PCI standard, web-application firewalls (WAFs) have received newfound interest from both consumers of security technologies, as well as from security researchers and potential attackers. Now that WAFs are a PCI-approved substitute for code reviews, expect many vendors to opt for this potentially less costly route to compliance. Of course, security researchers and potential attacks will increasingly....
|
|
With webapp protection now mandated by the PCI standard, web-application firewalls (WAFs) have received newfound interest from both consumers of security technologies, as well as from security researchers and potential attackers. Now that WAFs are a PCI-approved substitute for code reviews, expect many vendors to opt for this potentially less costly route to compliance. Of course, security researchers and potential attacks will increasingly....
|
|
Atlas: VulnCatcher: Fun with Vtrace and Programmatic Debugging
-
www.defcon.org
-
17 years ago
-
eng
Countless hours are spent researching vulnerabilities in proprietary and open source software for each bug found. Many indicators of potential vulnerabilities are visible both in the disassembly and debugging, if you know what to look for. How much can be automated? VulnCatcher illustrates the power of programmatic debugging using the VTRACE libraries for cross-platform debugging. atlas a disciple of the illustrious Skodo, has a histor..
|
|
Atlas: VulnCatcher: Fun with Vtrace and Programmatic Debugging
-
www.defcon.org
-
17 years ago
-
eng
Countless hours are spent researching vulnerabilities in proprietary and open source software for each bug found. Many indicators of potential vulnerabilities are visible both in the disassembly and debugging, if you know what to look for. How much can be automated? VulnCatcher illustrates the power of programmatic debugging using the VTRACE libraries for cross-platform debugging. atlas a disciple of the illustrious Skodo, has a histor..
|
|
Anthony Martinez & Thomas Bowen : Toasterkit, a modular NetBSD rootkit.
-
www.defcon.org
-
17 years ago
-
eng
NetBSD is a portable operating system for just about every architecture available. There is a notable lack of tools available for the penetration tester. In this talk we will present Toasterkit, a generic NetBSD rootkit. It has been tested on i386, Mac PPC, and VAX systems. Anthony Martinez is a system administrator for the New Mexico Tech Computer Center, and an undergraduate Computer Science student at the university. Thomas B..
|
|
Anthony Martinez & Thomas Bowen : Toasterkit, a modular NetBSD rootkit.
-
www.defcon.org
-
17 years ago
-
eng
NetBSD is a portable operating system for just about every architecture available. There is a notable lack of tools available for the penetration tester. In this talk we will present Toasterkit, a generic NetBSD rootkit. It has been tested on i386, Mac PPC, and VAX systems. Anthony Martinez is a system administrator for the New Mexico Tech Computer Center, and an undergraduate Computer Science student at the university. Thomas B..
|
|
Anton Kapela & Alex Pilosov: Stealing The Internet - A Routed, Wide-area, Man in the Middle Attack
-
www.defcon.org
-
17 years ago
-
eng
In this presentation we're going to show Defcon how broken the Internet is, how helpless its users are without provider intervention, and how much apathy there is towards routing security. With the method described in this talk, an attacker is able to gain full control and visibility of all IP packets heading towards an arbitrary destination prefix on the Internet. From the perspective of the victims network, every inbound packet they....
|
|
Anton Kapela & Alex Pilosov: Stealing The Internet - A Routed, Wide-area, Man in the Middle Attack
-
www.defcon.org
-
17 years ago
-
eng
In this presentation we're going to show Defcon how broken the Internet is, how helpless its users are without provider intervention, and how much apathy there is towards routing security. With the method described in this talk, an attacker is able to gain full control and visibility of all IP packets heading towards an arbitrary destination prefix on the Internet. From the perspective of the victims network, every inbound packet they....
|
|
This presentation will cover a variety of topics of interest to anyone on a cellphone network in the US. I'm going to cover how to use your own backends for MMS and WAP access, unlock Bluetooth tethering, and circumvent some of the more obnoxious carrier restrictions. Of course, the best part is baking your own firmware and running your own code. I'll provide an overview of the processes necessary to do so, a quick rundown of what you can....
|
|
This presentation will cover a variety of topics of interest to anyone on a cellphone network in the US. I'm going to cover how to use your own backends for MMS and WAP access, unlock Bluetooth tethering, and circumvent some of the more obnoxious carrier restrictions. Of course, the best part is baking your own firmware and running your own code. I'll provide an overview of the processes necessary to do so, a quick rundown of what you can....
|
|
Adam Bregenzer: Buying Time- What is your Data Worth? ( A generalized Solution to distributed Brute Force attacks)
-
www.defcon.org
-
17 years ago
-
eng
Brute Force attacks are often marginalized as a user issue or discounted as a non-issue because of sufficient password complexity. Because rainbow tables have provided a re-invigoration of this type of attack, maintaining password security is simply not enough. In this session, I will be releasing a framework for easily creating a brute force attack tool that is both multithreaded and distributed across multiple machines. As computing power....
|
|
Adam Bregenzer: Buying Time- What is your Data Worth? ( A generalized Solution to distributed Brute Force attacks)
-
www.defcon.org
-
17 years ago
-
eng
Brute Force attacks are often marginalized as a user issue or discounted as a non-issue because of sufficient password complexity. Because rainbow tables have provided a re-invigoration of this type of attack, maintaining password security is simply not enough. In this session, I will be releasing a framework for easily creating a brute force attack tool that is both multithreaded and distributed across multiple machines. As computing power....
|
|
The Dark Tangent & Joe "Kingpin" Grand: Welcome & Making of the Badge Talk
-
www.defcon.org
-
17 years ago
-
eng
The Dark Tangent welcomes the Defcon 16 attendees at the start of the conference. For the third year in a row, Kingpin has had the honor of designing the DEFCON Badge. No longer just a boring piece of passive material, the badge is now a full-featured, active electronic product. If you're up early enough and interested in details of the entire development process of the badge, from initial concept drawings to prototype electronics to c....
|
|
The Dark Tangent & Joe "Kingpin" Grand: Welcome & Making of the Badge Talk
-
www.defcon.org
-
17 years ago
-
eng
The Dark Tangent welcomes the Defcon 16 attendees at the start of the conference. For the third year in a row, Kingpin has had the honor of designing the DEFCON Badge. No longer just a boring piece of passive material, the badge is now a full-featured, active electronic product. If you're up early enough and interested in details of the entire development process of the badge, from initial concept drawings to prototype electronics to c....
|
|
The full power of Oracle’s diagnostic events, part 1: Syntax for KSD debug event handling
-
tanelpoder.com
-
17 years ago
-
eng
There’s a recent thread in Oracle-L about deadlocks and a recommendation to dump various instance information when the deadlock happens. A deadlock trace dumps some useful things automatically, but sometimes you want more, especially in RAC environment. So is it possible to make Oracle dump additional things when the deadlock event happens? Yes it is and it’s doable with Oracle diagnostic event handling infrastructure. First I’ll take....
|
|
The full power of Oracle’s diagnostic events, part 1: Syntax for KSD debug event handling
-
tanelpoder.com
-
17 years ago
-
eng
There’s a recent thread in Oracle-L about deadlocks and a recommendation to dump various instance information when the deadlock happens. A deadlock trace dumps some useful things automatically, but sometimes you want more, especially in RAC environment. So is it possible to make Oracle dump additional things when the deadlock event happens? Yes it is and it’s doable with Oracle diagnostic event handling infrastructure. First I’ll take....
|
|
Cool, just discovered: if you’re using the (UNIX command-line program) “less” to view a file, you can hit the “v” character to open the file in “vi”!
|