«
Expand/Collapse
122 items tagged "asia"
Related tags:
tags [+],
black hat [+],
security authors [+],
paper [+],
attacking [+],
web [+],
understanding [+],
david litchfield [+],
kenneth geers [+],
hacking [+],
geers [+],
windows [+],
web application [+],
vulnerabilities [+],
network [+],
forensics [+],
warfare [+],
taipei [+],
shaun clowes [+],
shah tags [+],
russ rogers tags [+],
russ rogers [+],
riley eller [+],
reverse engineering [+],
martin khoo [+],
malware [+],
laws [+],
joe grand [+],
hardware hacking [+],
exploiting [+],
cyberspace [+],
buffer [+],
black [+],
advanced [+],
Hardware [+],
slides [+],
x event [+],
walt tags [+],
virtualization [+],
virtual [+],
van der walt [+],
turn [+],
tim mullen [+],
threat [+],
terrorism [+],
technology authors [+],
tea [+],
tcp [+],
taiwan [+],
tables [+],
system [+],
symbian [+],
sql injection [+],
sql [+],
social engineering [+],
side [+],
shawn moyer [+],
setiri [+],
seki tags [+],
security vulnerabilities [+],
saumil shah [+],
satan [+],
rfid [+],
read [+],
public transportation services [+],
pl sql [+],
overflow [+],
oracle [+],
optimized [+],
ops [+],
online [+],
office documents [+],
office [+],
obfuscated [+],
ntlm [+],
nathan mcfeters [+],
nathan hamiel [+],
moyer [+],
mobile devices [+],
mac osx [+],
mac os x [+],
mac os [+],
list [+],
legal [+],
kingdom [+],
keys to the kingdom [+],
keys [+],
johnny long [+],
jeremiah grossman [+],
jennifer granick [+],
java virtual machine [+],
java [+],
japan [+],
jaco van [+],
international [+],
internal networks [+],
internal [+],
ida pro [+],
hypervisor [+],
harald welte [+],
hacking mac [+],
grossman [+],
greg hoglund [+],
graan [+],
google [+],
gerhard eschelbeck [+],
flake [+],
flag games [+],
flag [+],
fanboys [+],
exploitation techniques [+],
engineering [+],
dang [+],
dan kaminsky [+],
cyberterrorism [+],
covert channel [+],
cookie [+],
computer [+],
collin mulliner [+],
client [+],
chris eagle [+],
charlie miller [+],
chaos communication congress [+],
card [+],
capture [+],
capital taipei [+],
buffer overflow [+],
bruce dang [+],
black ops [+],
art [+],
architectures [+],
application [+],
Tools [+],
authors [+],
zane lackey [+],
xssploitation [+],
writing secure code [+],
worms [+],
world [+],
winny [+],
windows nt security [+],
win [+],
wifi [+],
websites [+],
web hacks [+],
web hacking [+],
web assessment [+],
vulns [+],
vulnerability assessment [+],
vulnerability [+],
voip [+],
vista [+],
van beek [+],
usage [+],
update [+],
unix ftp [+],
unix [+],
trying [+],
truths [+],
trees [+],
tracking [+],
track [+],
tool [+],
three truths [+],
threats [+],
thorsten holz [+],
thorsten [+],
thomas c. waszak [+],
thomas c [+],
thinking [+],
thepiratebay [+],
terminal [+],
technique [+],
techie [+],
targeted [+],
takayuki sugiura [+],
syscan [+],
swindlers [+],
survey result [+],
survey [+],
super [+],
subverting [+],
strategy tactics [+],
stephen dugan [+],
south east [+],
sony playstation [+],
sony hack [+],
sony [+],
software development [+],
social responsibility [+],
sns [+],
six degrees [+],
sites [+],
sip [+],
singapore [+],
shiva [+],
shellcode [+],
security windows [+],
security tags [+],
security review [+],
security guide [+],
security architectures [+],
securing [+],
secure [+],
science [+],
scanning [+],
scammers [+],
save [+],
s.k. chong [+],
russia [+],
rootkit [+],
revisited [+],
review [+],
remote [+],
reloaded [+],
raided [+],
prevention mechanism [+],
post mortem [+],
post [+],
playstation [+],
pierre noel tags [+],
pierre noel [+],
phishing [+],
perspectives [+],
perspective [+],
paul bhm [+],
parsing [+],
paranoid [+],
p security [+],
online scammers [+],
one [+],
non common [+],
nimda [+],
new [+],
neutralizing [+],
networks [+],
networked [+],
network forensics [+],
nature [+],
mosdef [+],
mortem [+],
moniz [+],
money [+],
microcosm [+],
measuring [+],
meaning [+],
maynor [+],
marcus ranum [+],
management authors [+],
management [+],
malicious [+],
malaysia government [+],
malaysia [+],
making money on the web [+],
machine [+],
low [+],
logons [+],
lindner [+],
laurent oudot [+],
larry leibrock [+],
language [+],
lackey [+],
kernel windows [+],
kernel [+],
kawaguchi [+],
joint [+],
joanna rutkowska [+],
jeremy rauch [+],
jeremiah [+],
jay beale [+],
japanese landscape [+],
japanese [+],
ipv [+],
ips [+],
intrusion detection [+],
intrusion [+],
intranet websites [+],
intranet [+],
interpreted [+],
intelligence [+],
input [+],
injection [+],
information security community [+],
information gathering [+],
information [+],
increasingly sophisticated [+],
identifying [+],
icmp [+],
http [+],
honeypots [+],
holes [+],
ho chi minh city [+],
hiroshi kawaguchi [+],
hideaki [+],
harry [+],
haroon [+],
hangzhou [+],
hacks [+],
gsm infrastructure [+],
gsm [+],
graph [+],
government [+],
get [+],
georg wicherski [+],
gathering [+],
gallery [+],
fyodor tags [+],
ftp servers [+],
front [+],
foreign [+],
forcing [+],
fixing [+],
fingerprinting [+],
felix [+],
falling [+],
fail [+],
epassports [+],
environment [+],
encoding [+],
emmanuel gadaix [+],
east asian country [+],
dugan [+],
door [+],
dominos [+],
domino event [+],
domino [+],
dominique brezinski [+],
dominique [+],
dmca [+],
disclosure law [+],
dirty [+],
detection [+],
detect [+],
dependencies [+],
degrees [+],
day [+],
david maynor [+],
dave aitel [+],
database security [+],
database [+],
darren bilby [+],
darknet [+],
dan moniz [+],
cyber vandals [+],
cyber threats [+],
cyber crime [+],
cyber [+],
crime authors [+],
conference [+],
computer forensics [+],
common security [+],
common [+],
code authors [+],
code [+],
cisco security [+],
cisco event [+],
chris hurley tags [+],
chris hurley [+],
chi minh city [+],
character encoding [+],
character [+],
change [+],
casing [+],
card access [+],
capture the flag [+],
buffer overflows [+],
brute [+],
bruce schneier [+],
botnet [+],
binary [+],
binaries [+],
based buffer overflow [+],
bait [+],
automated [+],
auditing [+],
attack trees [+],
attack [+],
assessment techniques [+],
assessment [+],
art and science [+],
arkin tags [+],
arian evans [+],
architecture [+],
arai [+],
anti [+],
anonymous [+],
analysis [+],
alexander eisen [+],
alex stamos [+],
ajax [+],
aiko tags [+],
aggressive [+],
Wireless [+],
Issues [+],
ExploitsVulnerabilities [+],
Bugs [+],
32 one way [+],
audio [+],
security [+],
security event [+]
-
-
21:40
»
SecDocs
Authors:
Harald Welte Tags:
RFID bank Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: How to reverse engineer the data format of a real-world RFID based debit card system. One of Asia’s most popular electronic payment systems uses insecure technology. The EasyCard system, established in 2001, is the most popular stored-valued card in Taiwan. With more than 18 million issued cards, it is the predominant means of paying for public transportation services in the capital Taipei. In 2010, use of the EasyCard was extended beyond transportation. Card holders can now pay in all major convenience stores like 7eleven, coffe shops like Starbucks and and major retail companies like SOGO. Despite the large fraud potential, the EasyCard system uses the MIFARE Classic RFID technology, whose proprietary encryption cipher CRYPTO1 relied on obscurity and was first publicly broken several years ago at 24C3 This presentation analyzes the results of combining the practical attacks on the MIFARE Classic CRYPTO1 system in the context of the EasyCard payment system. It describes the process of reverse- engineering the actual content of the card to discover the public transportation transaction log, the account balance and how the daily spending limit work. Furthermore, the talk will present how fundamentally flawed the system is, and how easy it is to add or subtract monetary value to/from the card. Cards manipulated as described in the talk have been accepted by the payment system.
-
21:40
»
SecDocs
Authors:
Harald Welte Tags:
RFID bank Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: How to reverse engineer the data format of a real-world RFID based debit card system. One of Asia’s most popular electronic payment systems uses insecure technology. The EasyCard system, established in 2001, is the most popular stored-valued card in Taiwan. With more than 18 million issued cards, it is the predominant means of paying for public transportation services in the capital Taipei. In 2010, use of the EasyCard was extended beyond transportation. Card holders can now pay in all major convenience stores like 7eleven, coffe shops like Starbucks and and major retail companies like SOGO. Despite the large fraud potential, the EasyCard system uses the MIFARE Classic RFID technology, whose proprietary encryption cipher CRYPTO1 relied on obscurity and was first publicly broken several years ago at 24C3 This presentation analyzes the results of combining the practical attacks on the MIFARE Classic CRYPTO1 system in the context of the EasyCard payment system. It describes the process of reverse- engineering the actual content of the card to discover the public transportation transaction log, the account balance and how the daily spending limit work. Furthermore, the talk will present how fundamentally flawed the system is, and how easy it is to add or subtract monetary value to/from the card. Cards manipulated as described in the talk have been accepted by the payment system.
-
-
21:45
»
SecDocs
-
21:45
»
SecDocs
-
21:45
»
SecDocs
-
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
-
21:58
»
SecDocs
-
21:58
»
SecDocs
-
21:58
»
SecDocs
-
21:58
»
SecDocs
-
21:58
»
SecDocs
-
21:58
»
SecDocs
-
-
21:32
»
SecDocs
-
21:32
»
SecDocs
-
21:32
»
SecDocs
-
12:37
»
SecDocs
-
-
13:32
»
SecDocs
-
-
21:35
»
SecDocs
-
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
2:04
»
SecDocs
-
2:01
»
SecDocs
-
1:59
»
SecDocs
-
1:57
»
SecDocs
-
1:55
»
SecDocs
-
1:50
»
SecDocs
-
-
21:42
»
SecDocs
-
21:42
»
SecDocs
-
21:42
»
SecDocs
-
21:42
»
SecDocs
-
21:42
»
SecDocs
-
5:43
»
SecDocs
-
5:40
»
SecDocs
-
5:38
»
SecDocs
-
5:34
»
SecDocs
-
5:31
»
SecDocs
-
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
2:38
»
SecDocs
-
2:38
»
SecDocs
-
2:28
»
SecDocs
-
2:27
»
SecDocs
-
2:26
»
SecDocs
-
2:25
»
SecDocs
-
2:23
»
SecDocs
-
2:22
»
SecDocs
-
2:20
»
SecDocs
-
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
-
21:52
»
SecDocs
-
21:52
»
SecDocs
-
21:52
»
SecDocs
-
21:52
»
SecDocs
-
21:52
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:43
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
-
21:29
»
SecDocs
-
21:29
»
SecDocs
-
21:29
»
SecDocs
-
21:29
»
SecDocs
-
-
11:32
»
SecDocs
-
-
13:03
»
SecDocs
-
-
2:18
»
SecDocs
-
2:18
»
SecDocs
-
2:18
»
SecDocs
-
2:18
»
SecDocs
-
-
3:25
»
SecDocs
-
3:25
»
SecDocs
-
3:25
»
SecDocs
-
3:25
»
SecDocs
-
3:25
»
SecDocs
-
-
1:52
»
SecDocs
-
1:52
»
SecDocs
-
-
11:23
»
SecDocs
-
11:23
»
SecDocs
-
11:18
»
SecDocs
-
11:16
»
SecDocs
-
11:11
»
SecDocs
-
-
13:15
»
SecDocs
-
10:54
»
SecDocs
-
-
13:16
»
SecDocs
-
13:14
»
SecDocs
-
13:11
»
SecDocs
-
11:47
»
SecDocs
-
11:23
»
SecDocs
-
-
12:00
»
Packet Storm Security Recent Files
SyScan 10 Call For Papers - The Symposium on Security for Asia Network aims to be a very different security conference from the rest of the security conferences that the information security community in Asia has come to be so familiar and frustrated with. SyScan is a non-product, non-vendor biased security conference. It is the aspiration of SyScan to congregate in Asia the best security experts in their various fields, to share their research, discovery and experience with all security enthusiasts in Asia. This year SyScan will be held in Singapore, Hangzhou, Taipei, and Ho Chi Minh City.