|
Ferdinand Schober - Gaming in the Glass Safe - Games DRM & Privacy
-
www.defcon.org
-
15 years ago
-
eng
DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....
|
|
Ferdinand Schober - Gaming in the Glass Safe - Games DRM & Privacy
-
www.defcon.org
-
15 years ago
-
eng
DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....
|
|
Ferdinand Schober - Gaming in the Glass Safe - Games DRM & Privacy
-
www.defcon.org
-
15 years ago
-
eng
DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....
|
|
Francisco Amato & Federico Kirschbaum - Evilgrade, You Still Have Pending Upgrades?
-
www.defcon.org
-
15 years ago
-
eng
Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....
|
|
Francisco Amato & Federico Kirschbaum - Evilgrade, You Still Have Pending Upgrades?
-
www.defcon.org
-
15 years ago
-
eng
Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....
|
|
Francisco Amato & Federico Kirschbaum - Evilgrade, You Still Have Pending Upgrades?
-
www.defcon.org
-
15 years ago
-
eng
Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....
|
|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Frank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
-
www.defcon.org
-
15 years ago
-
eng
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....
|
|
frank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
-
www.defcon.org
-
15 years ago
-
eng
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Learn how to crack crypto contests like a pro. The speaker has awarded half a dozen free round-trip plane tickets to previous contest winners. Maybe you'll be next. From the daily newspaper puzzle to badge contests to codes that keep the National Security Agency awake at night, it all comes down to intuition, perspiration, and math skillz. G. Mark Hardy has been providing information security expertise to government, military, and comm....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Behold! Billions of computers are infected with spyware every decade! But how! And why! Let's join our host as he takes you behind the curtain of the mysterious spyware industry. This will be a high level discussion with no technical knowledge needed. I'll be covering how I ended up writing spyware, what the software was capable of, how it was deployed onto millions of machines, how all the money was made (not how you'd expect) and how....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
Greg Conti - Our Instrumented Lives: Sensors, Sensors, Everywhere...
-
www.defcon.org
-
15 years ago
-
eng
Make no mistake, your analog life is under siege. Virtually every facet of your day to day existence is being sampled, digitized, aggregated, collated, shared, and reality mined. Whether the reason is to support your friendly neighborhood targeted advertiser or to help win a war on terror, a thickening web of sensors tracks our day to day existence in the physical world. Sensors are everywhere: our sneakers, cell phones, appliances, game co....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
The proprietary protocol developed by Adobe Systems for streaming audio, video and data over the Internet, the ëReal Time Messaging Protocol- (RTMP) and the proprietary protocol created by Macromedia used for streaming video and DRM, -Encrypted Real Time Messaging Protocol- (RTMPE) implementations for MySpace use security through obscurity and actually provide zero security. This talk will describe methods and demonstrate how to downlo....
|
|
CyberWar has been a controversial topic in the past few years. Some say the the mere term is an error. CyberCrime on the other hand has been a major source of concern, as lack of jurisdiction and law enforcement have made it one of organized crime's best sources of income. In this talk we will explore the uncharted waters between CyberCrime and CyberWarfare, while mapping out the key players (mostly on the state side) and how past even....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Itzhak "zuk" Avraham - Exploitation on ARM - Technique and Bypassing Defense Mechanisms
-
www.defcon.org
-
15 years ago
-
eng
In this presentation there will be covered (from scratch) quick talk on security mechanisms on X86 and how to bypass them, how exploits are being used on X86 and why they won't work as is on ARM, How to approach ARM assembly from hacker point of view and how to write exploits in the proper way for a remote and local attacker on ARM, what are the options for ARM hacker, etc. This presentation starts from the very basics of ARM assembly ....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
Jack Daniel & Panel - PCI, Compromising Controls and Compromising Security
-
www.defcon.org
-
15 years ago
-
eng
PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reason....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
James Arlen - SCADA and ICS for Security Experts: How to Avoid Cyberdouchery
-
www.defcon.org
-
15 years ago
-
eng
The traditional security industry has somehow decided that they are the white knights who are going to save everyone from the horror of insecure powergrids, pipelines, chemical plants, and cookie factories. Suddenly, every consultant is an expert and every product fixes SCADA. And because they don't know what the hell they're talking about -- 'fake it till ya make it' doesn't work -- they're making all of us look stupid. Attendees will....
|
|
All significant modern applications are ported to the web. Even with custom applications, there is at least one web-based component. Web applications are partially dependent on web clients and are continuously part of the security equation. These issues manifest in ways that make the user vulnerable. For example, privacy vulnerabilities are demonstrated with the EFF's Panopticlick browser fingerprinting project. Whether the weakness is priv....
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|
|
Jason Scott - You're Stealing It Wrong! 30 Years of Inter-Pirate Battles
-
www.defcon.org
-
15 years ago
-
eng
Historian Jason Scott walks through the many-years story of software piracy and touches on the tired debates before going into a completely different direction - the interesting, informative, hilarious and occasionally obscene world of inter-pirate-group battles. A multi-media extravaganza of threats, CSI-level accusations and evidence trails, decades of insider lingo, and demonstrations of how the more things change, the more they still ha..
|