|
Tottenkoph - Good Vibrations Hacking Motion Sickness on the Cheap - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Good Vibrations: Hacking Motion Sickness on the Cheap Tottenkoph consultant, crypto-fiend, hacker, and awesome chix0r Motion sickness has been an issue since man learned how to travel by means other than by foot, with the earliest recorded cases dating back to ancient Greece. Although the problem has existed for such a long time, there has been no documented case of a cure for all forms and severities of motion sickness and the ..
|
|
Tottenkoph - Good Vibrations Hacking Motion Sickness on the Cheap - Slides
-
www.defcon.org
-
16 years ago
-
eng
Good Vibrations: Hacking Motion Sickness on the Cheap Tottenkoph consultant, crypto-fiend, hacker, and awesome chix0r Motion sickness has been an issue since man learned how to travel by means other than by foot, with the earliest recorded cases dating back to ancient Greece. Although the problem has existed for such a long time, there has been no documented case of a cure for all forms and severities of motion sickness and the ..
|
|
Dominic Spill Michael Ossmann and Mark Steward - Bluetooth Smells like Chicken
-
www.defcon.org
-
16 years ago
-
eng
Bluetooth, Smells Like Chicken Dominic Spill Security Researcher Michael Ossmann Wireless Security Researcher Mark Steward Security Researcher Bluetooth traffic analysis is hard. Whilst most 802.11 chips support promiscuous mode, Bluetooth dongles cannot monitor all traffic due to a pseudo-random frequency hopping system. Previous attempts have recovered a small number of channels using software radio techniques but have required....
|
|
Dominic Spill Michael Ossmann and Mark Steward - Bluetooth Smells like Chicken - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Bluetooth, Smells Like Chicken Dominic Spill Security Researcher Michael Ossmann Wireless Security Researcher Mark Steward Security Researcher Bluetooth traffic analysis is hard. Whilst most 802.11 chips support promiscuous mode, Bluetooth dongles cannot monitor all traffic due to a pseudo-random frequency hopping system. Previous attempts have recovered a small number of channels using software radio techniques but have required....
|
|
Dominic Spill Michael Ossmann and Mark Steward - Bluetooth Smells like Chicken - Slides
-
www.defcon.org
-
16 years ago
-
eng
Bluetooth, Smells Like Chicken Dominic Spill Security Researcher Michael Ossmann Wireless Security Researcher Mark Steward Security Researcher Bluetooth traffic analysis is hard. Whilst most 802.11 chips support promiscuous mode, Bluetooth dongles cannot monitor all traffic due to a pseudo-random frequency hopping system. Previous attempts have recovered a small number of channels using software radio techniques but have required....
|
|
Douglas C Merrill - Is that you Baby or Just a Bridge in the Sky
-
www.defcon.org
-
16 years ago
-
eng
Is That You, Baby, or Just a Bridge in the Sky? Douglas C. Merrill Douglas C. Merrill was Chief Operating Officer of New Music for EMI Records and President of EMI’s Digital Business from 2008 to 2009. In those roles, he was responsible for the operation of the new music creation business, and led all of EMI’s digital strategy, innovation, business development, supply chain and global technology activities. Dr. Merrill served....
|
|
Douglas C Merrill - Is that you Baby or Just a Bridge in the Sky - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Is That You, Baby, or Just a Bridge in the Sky? Douglas C. Merrill Douglas C. Merrill was Chief Operating Officer of New Music for EMI Records and President of EMI’s Digital Business from 2008 to 2009. In those roles, he was responsible for the operation of the new music creation business, and led all of EMI’s digital strategy, innovation, business development, supply chain and global technology activities. Dr. Merrill served....
|
|
Douglas C Merrill - Is that you Baby or Just a Bridge in the Sky - Slides
-
www.defcon.org
-
16 years ago
-
eng
Is That You, Baby, or Just a Bridge in the Sky? Douglas C. Merrill Douglas C. Merrill was Chief Operating Officer of New Music for EMI Records and President of EMI’s Digital Business from 2008 to 2009. In those roles, he was responsible for the operation of the new music creation business, and led all of EMI’s digital strategy, innovation, business development, supply chain and global technology activities. Dr. Merrill served....
|
|
Doppelganger: The Web's Evil Twin Edward Zaborowski Senior Security Engineer, Apptis Users and administrators alike surf the web assuming that, for the most part, what they are looking at is what the website served to their browser; however, an attacker can deploy a malicious proxy, altering responses and requests, as well as potentially stealing sensitive data, all without a user being aware. In this presentation I will discuss....
|
|
Edward Zaborowski - Doppleganger The Webs Evil Twin - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Doppelganger: The Web's Evil Twin Edward Zaborowski Senior Security Engineer, Apptis Users and administrators alike surf the web assuming that, for the most part, what they are looking at is what the website served to their browser; however, an attacker can deploy a malicious proxy, altering responses and requests, as well as potentially stealing sensitive data, all without a user being aware. In this presentation I will discuss....
|
|
Metasploit Goes Web Efrain Torres Metasploit Team This topic will present and discuss the new Metasploit plugin for web exploitation and assessment. WMAP is part of the Metasploit framework and it is build with a different approach compared to other open source alternatives and commercial scanners. WMAP is not build around any browser or spider for data capture and manipulation and as test modules are implemented as auxiliary modules....
|
|
Metasploit Goes Web Efrain Torres Metasploit Team This topic will present and discuss the new Metasploit plugin for web exploitation and assessment. WMAP is part of the Metasploit framework and it is build with a different approach compared to other open source alternatives and commercial scanners. WMAP is not build around any browser or spider for data capture and manipulation and as test modules are implemented as auxiliary modules....
|
|
Metasploit Goes Web Efrain Torres Metasploit Team This topic will present and discuss the new Metasploit plugin for web exploitation and assessment. WMAP is part of the Metasploit framework and it is build with a different approach compared to other open source alternatives and commercial scanners. WMAP is not build around any browser or spider for data capture and manipulation and as test modules are implemented as auxiliary modules....
|
|
Efstratios Gavas - Asymetric Defense How to fight off the NSA Red Team
-
www.defcon.org
-
16 years ago
-
eng
Asymmetric Defense: How to Fight Off the NSA Red Team with Five People or Less Efstratios L. Gavas Assistant Professor, United States Merchant Marine Academy The NSA sponsors an annual Cyber Defense Exercise (CDX) to raise awareness of and help develop cyber defense skills in our armed forces. This is the story of how the United Stated Merchant Marine Academy, the smallest of the five undergraduate service academies, has managed to h....
|
|
Efstratios Gavas - Asymetric Defense How to fight off the NSA Red Team - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Asymmetric Defense: How to Fight Off the NSA Red Team with Five People or Less Efstratios L. Gavas Assistant Professor, United States Merchant Marine Academy The NSA sponsors an annual Cyber Defense Exercise (CDX) to raise awareness of and help develop cyber defense skills in our armed forces. This is the story of how the United Stated Merchant Marine Academy, the smallest of the five undergraduate service academies, has managed to h....
|
|
Efstratios Gavas - Asymetric Defense How to fight off the NSA Red Team - Slides
-
www.defcon.org
-
16 years ago
-
eng
Asymmetric Defense: How to Fight Off the NSA Red Team with Five People or Less Efstratios L. Gavas Assistant Professor, United States Merchant Marine Academy The NSA sponsors an annual Cyber Defense Exercise (CDX) to raise awareness of and help develop cyber defense skills in our armed forces. This is the story of how the United Stated Merchant Marine Academy, the smallest of the five undergraduate service academies, has managed to h....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Egypt - Automatic Browser Fingerprinting and Exploitation with Metasploit - Slides
-
www.defcon.org
-
16 years ago
-
eng
Using Guided Missiles in Drive-Bys: Automatic browser fingerprinting and exploitation with Metasploit Egypt Core Developer, Metasploit Project The blackhat community has been using client-side exploits for several years now. Multiple commercial suites exist for turning webservers into malware distribution centers. Unfortunately for the pentester, acquiring these tools requires sending money to countries with no extradition treaties, ....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Endgrain Dan Kaminsky and Tiffany Rad - Hello My Name is hostname - Slides
-
www.defcon.org
-
16 years ago
-
eng
Hello, My Name is /hostname/ Endgrain Student of computer science at the University of Southern Maine Tiffany Rad Part-time Professor, Computer Science Department, University of Southern Maine Dan Kaminsky Director of Pen Testing, IOActive It is widely known that MAC addresses are spoofable, however many access control models rely on them to uniquely identify devices. When host names are set to be user's real names and are broadc....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Erez Metula - Managed Code Rootkits Hooking into Runtime Enviroments - Slides
-
www.defcon.org
-
16 years ago
-
eng
Managed Code Rootkits - Hooking into Runtime Environments Erez Metula Application Security Department manager, 2BSecure This presentation introduces a new concept of application level rootkit attacks on managed code environments, enabling an attacker to change the language runtime implementation, and to hide malicious code inside its core. Taking the ".NET Rootkits" concepts a step further, while covering generic methods of malware d....
|
|
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
etd - Dradis Framework Sharing Information Will Get You Root - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
etd - Dradis Framework Sharing Information Will Get You Root - Slides
-
www.defcon.org
-
16 years ago
-
eng
Dradis Framework - Sharing Information will get you Root etd Senior Security Consultant, NGS Software dradis is not a dream any more. It is a mature framework. Information sharing taken to a new level. If you are in the security industry is because you want to break stuff. Not because you like wasting your time. Not because you love to write reports. Not because you enjoy doing things twice, or doing them manually if they could be sc....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Fred Von Lohman and Jennifer Granick - Jailbreaking and the Law of Reversing - Slides
-
www.defcon.org
-
16 years ago
-
eng
Jailbreaking and the Law of Reversing Fred Von Lohmann Senior Staff Attorney, EFF Jennifer Granick Civil Liberties Director, EFF Using jailbreaking of the iPhone as a primary example, the presentation will be an overview of the laws relating to reverse engineering of hardware and software. Developers who rely on reverse engineering face a thicket of potential legal obstacles, including license agreements, copyright, the Digita....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Router Exploitation FX of Phenoelit, Head, Recurity Labs GmbH Exploitation of active networking equipment has its own history and challenges. This session will take you through the full spectrum of possible attacks, what they yield and how the art of exploitation in that particular field evolved over the recent past to its present state. We will cover attacks on Cisco equipment and compare them to other specimen in the field, talk ab....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Introduction to WiMAX Hacking Goldy Pierce WiMAX is a new high speed, 802.16e, wide area broadband service that promises to replace 3G high speed networks. It is only being offered in a few cities across the country, but by 2012 it is estimated that it will be nation wide. Over the last decade, hackers have explored and demonstrated weaknesses in the security of WiFi, pushing the industry to come up with better security practices. ....
|
|
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Grant Jordan - Stealing Profits from Stock Market Spammers - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Grant Jordan - Stealing Profits from Stock Market Spammers - Slides
-
www.defcon.org
-
16 years ago
-
eng
Stealing Profits from Stock Market Spammers or: How I learned to Stop Worrying and Love the Spam Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "accidentally" emailed you, and a former Nigerian prince knows that you're just the man to safeguard his millions. But in 2007, while still a student at MIT, one particular kind caught my eye: ....
|
|
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Gregory Fleischer - Attacking Tor and the Application Layer - Video and Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Gregory Fleischer - Attacking Tor and the Application Layer - Slides
-
www.defcon.org
-
16 years ago
-
eng
Attacking Tor at the Application Layer Gregory Fleischer Security Researcher Surfing the web using Tor makes you invincible, right? Wrong! Between the technical deficiencies, web browser idiosyncrasies, Tor vulnerabilities, social engineering, and bone-headed user decisions, there is ample room for attack and exploitation. This presentation covers past and present application layer attacks against Tor. From practical hackin....
|
|
Haroon Meer and Marco Slaviero - Clobbering the Cloud And Slides
-
www.defcon.org
-
16 years ago
-
eng
Clobbering the Cloud Haroon Meer Technical Director, SensePost Marco Slaviero Cyber Fighter, SensePost Nicholas Arvanitis Senior Security Analyst, SensePost Cloud Computing dominates the headlines these days but like most paradigm changes this introduces new risks and new opportunities for us to consider. Some deep technical research has gone into the underlying technologies (like Virtualization) but to some extent this serves on....
|