|
If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....
|
|
If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....
|
|
Johnny Long was a relative forensics newbie who was faced with the challenge of hunting down the amazingly agile and paranoid "Knuth" from the best-selling Syngress 'stealing the Network? book series. In the story, Knuth melted down his hard drive platters and USB sticks before leaving the country, leaving any investigator next to no digital evidence. Fortunately for the good guys, Knuth left behind some oft-neglected hardware that left ..
|
|
Marce Luck & Tom Stracener: Hacking the EULA: Reverse Benchmarking Web Application Security Scanners
-
www.defcon.org
-
20 years ago
-
eng
Each year thousands of work hours are lost by security practitioners as time is spent sorting through web application security reports and separating out erroneous vulnerability data. Individuals must currently work through this process in a vacuum, as there is no publicly available information that is helpful. Restrictive EULAs (End User License Agreements) prohibit examining a signature code-base for common errors or signature flaws. Due ....
|
|
Any attacker can scam one or two users into revealing themselves, but do you know how to talk an entire community of smart hackers into weakening its anonymity? In spite of progress in traffic analysis, social engineering attacks remain the most effective way to break users' anonymity and one of the best force multipliers for traditional traffic analysis attacks. Why bother doing traffic analysis when you can trick users into isolating....
|
|
Nick Mathewson: TECHNICAL CHANGES SINCE YOU LAST HEARD ABOUT TOR
-
www.defcon.org
-
20 years ago
-
eng
There hasn't been a talk from the developers of Tor (the popular anonymity network) at Defcon since 2004. Since then, we've revised the protocols, added piles of new features to the software, tightened security, integrated more helper tools, made hard strategic decisions, and suffered growing pains. There have been new attacks, new defenses, new research, and new ideas. In this talk, I'll present the most important technical changes an....
|
|
Nate McFeters & Billy Rios: Biting the Hand that Feeds You - Storing and Serving Malicious Content From Well Known Web Servers
-
www.defcon.org
-
20 years ago
-
eng
What's in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In th....
|
|
Timing attacks have been exploited in the wild for ages. In recent times timing attacks have largely been relegated to use only by cryptographers and cryptanalysts. In this presentation SensePost analysts will show that timing attacks are still very much alive and kicking on the Internet and fairly prevalent in web applications (if only we were looking for them). The talk will cover SensePost-aTime (our new SQL Injection tool that operates ....
|
|
Charlie Miller: How smart is Intelligent Fuzzing - or - how stupid is Dumb Fuzzing?"
-
www.defcon.org
-
20 years ago
-
eng
Dynamic analysis, or fuzzing, is a popular method of finding security vulnerabilities in software. Fuzzing may be used by a developer to find potential problems as part of the quality-assurance process or may be used to find potential exploits in an existing software application. Fuzzing has grown in popularity because it is much easier (and often more effective) to generate and run arbitrary inputs than it is to perform a manual code audit....
|
|
More unlicensed bandwidth from TV!?! A long-term push to free up more wireless spectrum is expected to come to fruition this year as the FCC will open up unused TV channels ? dubbed ?white spaces? ? for unlicensed broadband use this fall, with full-blown availability in 2008 once the DTV transition takes place. Dell, Google, HP, Intel, Microsoft and Philips have joined together in the ?White Spaces Coalition? to lobby for a spec....
|
|
Penetration testing often focuses on individual vulnerabilities and services. This talk introduces a tactical approach that does not rely on exploiting known vulnerabilities. Using combination of new tools and obscure techniques, I will walk through the process of compromising an organization without the use of normal exploit code. Many of the tools will be made available as new modules for the Metasploit Framework. HD Moore is the di....
|
|
Dark Tangent never speaks at DEF CON because he thinks it is cheating.. but not for the 15th anniversary! Come listen to a behind the scenes account of what really happened during the "Cisco/ISS Gate" fiasco from 2005. Throughout the talk the audience will be asked what they would have done at key points and then learn what I chose to do. A cautionary and comical tale of what happens when communication breaks down. The Dark Tangent st..
|
|
NEW!! Advanced Data Recovery Material. Even people who think they know everything about a hard drive will be surprised at what they will learn in this presentation. Everyone will learn something new about hard drives and how to perform data recovery. We will lay it on the line and tell all! We will display All NEW Material and Animations on the inner workings of a hard drive. We will discuss rebuilding a hard drive and will teach you what ..
|
|
Shawn Moyer: (un)Smashing the Stack: Overflows, Countermeasures, and the Real World
-
www.defcon.org
-
20 years ago
-
eng
As of today, Vista, XP, 2K03, OS X, every major Linux distro, and each of the BSD's either contain some facet of (stack|buffer|heap) protection, or have one available that's relatively trivial to implement/enable. So, this should mean the end of memory corruption-based attacks as we know it, right? Sorry, thanks for playing. The fact remains that many (though not all) implementations are incomplete at best, and at worst are simply bull....
|
|
Alexander Muentz: Protecting your IT infrastructure from legal attacks- Subpoenas, Warrants and Transitive Trust. "
-
www.defcon.org
-
20 years ago
-
eng
You think your systems and data are safe from any attack. You fear no script kiddie. You get a +5 against social engineering. Yet a single subpoena can crack your junk open wide. A search warrant might leave you with an empty server room. The law might be the biggest threat to your users, systems and you. Learn how to plan for and react to search warrants, subpoenas and wiretaps. I?m going to speak about the law in an IT context, make i..
|
|
Event logging in Windows Vista is quite different in terms of the way events are stored on disk and the way they are used by applications. Vista uses a new encoding of event records that lends itself to much broader flexibility for searching events. This encoding has a direct impact on forensic examination of event logs, which will be discussed in this presentation. The impact of the new application programming interface (API) is no less im....
|
|
Video games are the most effective and accessible tool for hacking your physical and mental state, yet the potential impact of these technologies has yet to be exploited. In this presentation we will take you on a journey through video games -past, present and future-, dispelling the myths and emphasizing the realities, both positive and dark. We will also explain how different input devices can be used to improve the brai....
|
|
Danny O'Brien: Digital Rights Worldwide: Or How to Build a Global Hacker Conspiracy
-
www.defcon.org
-
20 years ago
-
eng
Hackers and tech users in the United States have long benefited from some long-lived institutions that have worked to helped defend and publicise their rights, including but not limited to EFF and DefCon itself. But the legal and political fights over DRM and copyright, privacy invasions, cybercrime round-ups and security scaremongering, are now increasingly international battles. How can hackers across the world build their own institution....
|
|
Brendan O'connor: Greater than 1: Defeating "strong" Authentication in Web Applications
-
www.defcon.org
-
20 years ago
-
eng
With Phishing, Fraud, and Identity Theft at peak levels, banks, credit unions, credit card companies, and other financial institutions are enhancing the security of their website authentication. This talk will cover the new methods of authentication, such as mutual authentication, device fingerprinting, out of band authentication, one time passwords, and knowledge base archives. We will analyze how these controls are intended to function, w....
|
|
STEVE ORRIN: The SOA/XML Threat Model and New XML/SOA/Web 2.0 Attacks & Threats
-
www.defcon.org
-
20 years ago
-
eng
Organizations that are implementing XML based systems, Web Services, Web 2.0 applications are discovering that there are security challenges unique to them that can surface throughout the various phases of lifecycle. Traditional network and application protection and infrastructure systems lack the functionality, performance, and operational efficiencies needed to provide a secure, cost effective solution. Web Services, SaaS and SOA provide....
|
|
Alfredo Ortega: OpenBSD remote Exploit and another IPv6 vulnerabilities
-
www.defcon.org
-
20 years ago
-
eng
OpenBSD is regarded as a very secure Operating System. This article details one of the few remote exploit against this system. A kernel shellcode is described, that disables the protections of the OS and installs a user-mode process. Several other possible techniques of exploitation are described. Several other ipv6-related vulnerabilities are described and disclosed. Alfredo Ortega: Born at Esquel, Chubut, Argentina on 1978. Worked on..
|
|
Chris Palmer & Alex Stamos: Breaking Forensics Software: Weaknesses in Critical Evidence Collection
-
www.defcon.org
-
20 years ago
-
eng
Across the world law enforcement, enterprises and national security apparatus utilize a small but important set of software tools to perform data recovery and investigations. These tools are expected to perform a large range of dangerous functions, such as parsing dozens of different file systems, email databases and dense binary file formats. Although the software we tested is considered a critical part of the investigatory cycle in the ....
|
|
Gadi Evron Moderator Andrew Fried IRS Thomas Grasso FBI Dan Hubbard Websense Dan Kaminsky IOActive Randy Vaughn Baylor Paul Vixie ISC Continuing our new tradition from last year, leading experts from different industries, academia and law enforcement will go on stage and participate in this panel, discussing the current threats on and to the Internet, from regular cyber-crime all the way to the mafia, and even some informat....
|
|
The Church of WiFi (reformed) returns to Las Vegas bigger and better than ever. Last year we brought you the first pre-computed rainbow tables for faster WPA cracking. This year, we've gone overboard and expanded the tables to places and sizes not dared before. Can you say: our own live distro? And that's not all: we're prostelytizing our wireless foo this year by hosting the Wireless Village, a place for tutorials, mini-presentat....
|
|
Myles Long & Panel: Self-Publishing and the Computer Underground
-
www.defcon.org
-
20 years ago
-
eng
Have you ever considered publishing your own book? Your own DVD? Self-publishing has been a part of the computer underground since its inception, from the Neon Knights to the Syndicate of London's recent book _End of Dayz_. This panel will discuss types of self-publishing (both on- and off-line) and their relevance to the computer underground. They will also discuss their personal experiences in self-publishing. Ample time for qu....
|
|
Deviant Ollam & Panel: Boomstick Fu: The Fundamentals of Physical Security at its Most Basic Level
-
www.defcon.org
-
20 years ago
-
eng
It seems that at every con nowadays there is at least one talk dedicated to physical security. Our servers and data can be encrypted and passworded with the latest algorithms, but that doesn't do the trick if someone marches them out the door when we're not looking. In the past, many physical security talks have focused on passive defense: locks that resist picking, safes which resist cracking, etc. However, sometimes....
|
|
Daniel Peck & Ben Feinstein: CaffeineMonkey: Automated Collection, Detection and Analysis of Malicious JavaScript
-
www.defcon.org
-
20 years ago
-
eng
The web browser is ever increasing in its importance to many organizations. Far from its origin as an application for fetching and rendering HTML, today's web browser offers an expansive attack surface to exploit. All the major browsers now include full-featured runtime engines for a variety of interpreted scripting languages, including the popular JavaScript. The web experience now depends more than ever on the ability of the browser to dy....
|
|
Imagine your only connection to the Internet was through a potentially hostile environment such as the Defcon wireless network. Worse, imagine all someone had to do to own you was to inject some html that runs a plugin or some clever javascript to bypass your proxy settings. Unfortunately, this is the risk faced by many users of the Tor anonymity network who use the default configurations of many popular browsers and other network software.....
|
|
As wi-fi becomes increasingly popular and as more layers of access control are added, the fact that a wireless access point exists becomes less interesting to us. The problem is that manually going through a long list of access points checking for interesting information is tedious at best. Wicrawl is a tool that will allow you to "crawl" through discovered access points with a series of plugins that implement common tools (nmap, aircr....
|
|
Novell's Identity Manager and related components are become fairly common in large networks. Identity management systems in general bring a number of security implications that are often not well understood. Even when best practices are followed, the system often has vulnerabilities that can be exploited. Since there seems to be little research into hacking identity management systems, the goal of this talk is to bring some recognition to ....
|
|
The fox is guarding the hen house, and both the fox and the hens are making a lot of money in the process. Such is the state of the security industry in 2007. For the last 15 years, we have been building security into our networks and applications using concepts like "defense in depth" and "layered security." It turns out, that the attackers are now leveraging our security systems against us. Worse, we have made the security industry ....
|
|
Danny Quist & Valsmith: Covert Debugging: Circumventing Software Armoring Techniques
-
www.defcon.org
-
20 years ago
-
eng
Software armoring techniques have increasingly created problems for reverse engineers and software analysts. As protections such as packers, run-time obfuscators, virtual machine and debugger detectors become common newer methods must be developed to cope with them. In this talk we will present our covert debugging platform named Saffron. Saffron is based upon dynamic instrumentation techniques as well as a newly developed page fault assist....
|
|
Widgets (or Gadgets) are small applications, which usually provide some kind of visual information or access to a frequently used function. Because widgets are in fact applications, they too can include malicious code. Furthermore, due to the simplicity of legitimate widgets, such as calculators and clocks, they are developed without security in mind. In this presentation, we will explain the three different types of widgets in detail....
|
|
Vivek Ramachandran: The Emperor Has No Cloak ? WEP Cloaking Exposed
-
www.defcon.org
-
20 years ago
-
eng
WEP Cloaking is a recently proposed anti-WEP-cracking technique that is claiming to be the savior of legacy WLAN devices still replying on WEP encryption. The WEP Cloaking mechanism is meant to be used in Wireless Intrusion Prevention Systems (WIPS) to protect WEP encrypted networks. The WEP Cloaking technique sends spoofed WEP encrypted packets a.k.a. ?chaff? into the air. These packets are specially crafted to try and confuse WEP crack....
|
|
Matt Richard: Beyond Vulnerability Scanning - Extrusion and Exploitability Scanning
-
www.defcon.org
-
20 years ago
-
eng
With this presentation we will demonstrate a new tool called eescan that automates extrusion and exploitability scanning using a client/server approach. Eescan will be released under the GPL and utilizes python to create an extensible framework for testing extrusion and exploit defenses. All network security systems have gaps. Layered security tries to cover the gaps with overlapping protections like firewalls, intrusion prevention, pr....
|
|
Billy Rios: Biting the Hand that Feeds You - Storing and Serving Malicous Content From Well Known Web Servers
-
www.defcon.org
-
20 years ago
-
eng
Whats in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In thi....
|
|
Every day billions of dollars pass through middleware, the unglamorous component of most enterprise applications. Middleware may be unglamorous, but even if billions of dollars doesn't interest you, it's bound to attract someone's interest sooner or later. Often security is addressed in the front-end web server and back-end database but the other components are often ignored. The reason for this can be a lack of understanding of the risks o....
|
|
Networks are central do almost everything that hackers do. Be they computer networks, peer-to-peer networks, information networks, or social networks, they are all around us and understanding them is the key to understanding both the strengths and vulnerabilities of our world. The speaker, a mathematician working in the field of complex networks, will introduce the modern mathematics of networks, and how it can be applied to real-world situ....
|
|
What in the world is a U.S. Navy officer (a Naval Flight Officer, no less) doing in the middle of Iraq? Electronic warfare, of course! The Church of WiFi presents an unclassified presentation of theprez98's experiences during his 9-month tour in Iraq. Embedded with Army units on the ground, theprez98 brought his expertise in electronic warfare to bear against the biggest threat to coalition forces - the improvised explosive device (IED). H....
|
|
Security is both a feeling and a reality. You can feel secure without actually being secure, and you can be secure even though you don't feel secure. In the industry, we tend to discount the feeling in favor of the reality, but the difference between the two is important. It explains why we have so much security theater that doesn't work, and why so many smart security solutions go unimplemented. Two different fields?behavioral economics an....
|
|
domain images; like MySpace or eBay. By uploading the following line of HTML to a community website,[img src="http://www.mydomain.com/executable.jpg?] you can launch a dynamic program that masquerades as a static image and capable of reading and writing cookies, analyzing referrer (and other browser) variables and access databases. It is even possible to create an image the causes a browser to execute JavaScript. A previous DEFCON Spe..
|
|
Too often, "Computer History" gets shoved into a forgotten bin of irrelevancy, devoid of use for lessons and understanding. Even more often, people often fail to realize they're making history themselves. Jason Scott will walk though the basics of computer history, what to save, how to ensure things last for future generations, or perhaps how to ensure it's never found again. Jason Scott is a hard-core computer historian now celeb..
|
|
Dror Shalev: A Crazy Toaster: Can Home Devices turn against us?
-
www.defcon.org
-
20 years ago
-
eng
A Crazy Toaster: Can Home Devices turn against us?" Home networking devices, wireless equivalents, hardware and technology raise new privacy and trust issues. Can Home Devices turn against us and spy on our home Network? Do we care if our Toaster sees us Naked? This talk will cover a scenario of "Crazy Toaster". Trojan device under Vista and XP environment, or software with TCP/IP capabilities like Routers, Media Players....
|
|
Utu is the Maori word for a system of revenge used by Maori society to provide social controls and retribution. Utu is also a protocol that uses cryptographic models of social interaction to allow peers to vote on their dislike of other peer's behavior. The goal of Utu is to experiment with the effects of bringing identity, reputation, and retribution to human communications on the Internet. A secondary goal is wiping ....
|