«
Expand/Collapse
409 items tagged "authors"
Related tags:
usa [+],
tor [+],
google [+],
slides [+],
hacking [+],
cisco event [+],
windows security [+],
roger dingledine [+],
mac os x [+],
mac os [+],
forensics [+],
charlie miller [+],
black [+],
x event [+],
tor event [+],
shah tags [+],
hat europe [+],
forensic [+],
de haas [+],
chaos communication congress [+],
browser [+],
wpa [+],
windows [+],
translation [+],
stephen dugan [+],
sohail ahmad [+],
setiri [+],
secure [+],
search [+],
papathanasiou [+],
nicholas j. percoco [+],
nac [+],
michael thumann [+],
malware [+],
lost in translation [+],
lindner [+],
johnny long [+],
john roecher michael [+],
jennifer granick [+],
intrusion detection [+],
felix [+],
engine [+],
droid [+],
domino event [+],
dingledine [+],
david litchfield [+],
database [+],
christian papathanasiou [+],
christian grothoff [+],
brown rob ragan [+],
bing [+],
attacking [+],
arkin tags [+],
ahmad tags [+],
tags [+],
vulnerabilities [+],
u.s. [+],
symbian [+],
security 2002 [+],
sassaman [+],
rich internet [+],
resilient [+],
ragan [+],
project [+],
michael brooks [+],
mentor [+],
massexploitation [+],
mark vincent yason [+],
mark vincent [+],
marisa fagan [+],
len sassaman [+],
lance spitzner [+],
kim jong il [+],
jong il [+],
joe grand [+],
introduction [+],
intelligence [+],
honeypots [+],
heap [+],
haroon [+],
fagan [+],
exploiting [+],
event [+],
europe [+],
dugan [+],
domino [+],
dennis brown tags [+],
dennis brown [+],
dave aitel [+],
d moore [+],
cyber army [+],
build [+],
botnet [+],
anonymity [+],
ajax [+],
abuse [+],
xss [+],
wouter aukema [+],
wifi [+],
web application [+],
web [+],
vulnerability disclosure [+],
vulnerability [+],
virus [+],
uri use [+],
uri event [+],
unpacking [+],
tunisia [+],
tor network [+],
timing [+],
tim wyatt [+],
thumann [+],
thomas akin [+],
tales [+],
syria [+],
stefano zanero [+],
spider [+],
social engineering [+],
sleeping giant [+],
simple [+],
server [+],
security failures [+],
security 2001 [+],
securing [+],
scott blake [+],
saumil shah [+],
runtime [+],
rooted [+],
rob carter tags [+],
rob carter [+],
ria [+],
reloaded [+],
project authors [+],
processors [+],
play [+],
phone [+],
permissions [+],
penetration [+],
patrick miller [+],
openleaks [+],
nick breese [+],
network privacy [+],
network [+],
nesbit [+],
nathan mcfeters [+],
nacattack [+],
mike perry tags [+],
mike perry [+],
metasploit [+],
marco slaviero [+],
mac osx [+],
lineberry [+],
leopard [+],
layer [+],
laws [+],
laurent oudot [+],
kevin mcpeake [+],
kernel [+],
joel eriksson [+],
job [+],
jay beale [+],
javascript [+],
java event [+],
james d. broesch [+],
jacob appelbaum [+],
jaco van [+],
international [+],
information operation [+],
information [+],
ids [+],
ian goldberg [+],
handshake [+],
h.d. moore tags [+],
greg hoglund [+],
graan [+],
goldberg [+],
games [+],
g. mark hardy [+],
future [+],
foca [+],
flake [+],
feng shui [+],
falling [+],
engineering [+],
dpi [+],
dom [+],
defeating [+],
decompilation [+],
deadly cocktail [+],
ddos attacks [+],
david richardson tim wyatt tags [+],
david richardson [+],
database security [+],
daniel domscheit [+],
cyber [+],
crypto [+],
crackstation [+],
cisco router [+],
cisco devices [+],
christopher tarnovsky [+],
christoph weber [+],
chris hurley tags [+],
chris hurley [+],
china [+],
chaos communication camp [+],
bruce potter [+],
brandon nesbit [+],
bluecoat [+],
billy rios [+],
attack [+],
art [+],
aren [+],
anthony lineberry [+],
alonso jose palazon [+],
alexander sotirov [+],
advanced [+],
Wireless [+],
11b [+],
asia [+],
paper [+],
yuan [+],
yersinia [+],
xssploitation [+],
x linux [+],
x kernel [+],
wouters [+],
worth [+],
worms [+],
worldwide [+],
world war ii [+],
world authors [+],
world [+],
wolf [+],
wlan [+],
wireless lan security [+],
winny [+],
windows kernel [+],
wilco [+],
wep [+],
webapp [+],
web hacks [+],
web hacking [+],
warez [+],
wardrive [+],
walter van holst [+],
walt tags [+],
vulnerability assessment [+],
vpn [+],
voip [+],
vlans [+],
video kim [+],
video digitizer [+],
van holst [+],
van heerden [+],
van ginkel [+],
van der walt [+],
van beek [+],
valleri [+],
val smith [+],
unique [+],
unforgivable [+],
understanding [+],
tyler [+],
turn [+],
truth [+],
trusted [+],
trust [+],
tricks [+],
tracks [+],
tor anonymity [+],
toolkit [+],
todd sabin [+],
timothy mullen [+],
threats [+],
thomas ryan tags [+],
thomas c. waszak [+],
thomas c [+],
theory [+],
test authors [+],
terminal [+],
tea [+],
taranis [+],
tapping [+],
takayuki sugiura [+],
tactical [+],
tables [+],
syscall [+],
synthesis [+],
surrounding [+],
stuxnet [+],
steve riley timothy bollefer [+],
steve riley [+],
steve christey [+],
stealth [+],
stack [+],
spyware [+],
sploits [+],
spike [+],
source [+],
somthing [+],
sohail [+],
social networking sites [+],
snort [+],
smoke [+],
smashing [+],
smartphone [+],
six degrees [+],
silver needle [+],
side channel [+],
shortcomings [+],
shoot [+],
shinder [+],
shewmaker [+],
shellcode [+],
shawn moyer [+],
shaun clowes [+],
shatter proofing [+],
seth fogie [+],
sensors [+],
seek [+],
security issues [+],
security design [+],
sean convery [+],
schoenefeld [+],
scenes [+],
scene [+],
scada [+],
sarah gordon tags [+],
sarah gordon [+],
ryan permeh [+],
ruby [+],
routing [+],
routers [+],
rootkits [+],
room 101 [+],
room [+],
rolles [+],
rolf rolles [+],
rogue [+],
robin sage [+],
robin [+],
robert baird [+],
rip [+],
rick smith [+],
rfid [+],
reverse engineering [+],
retention [+],
reporting [+],
renaud deraison [+],
renaud bidou [+],
record [+],
razor [+],
rashid tags [+],
rashid [+],
ralf spenneberg [+],
proxying [+],
protocol attacks [+],
protocol [+],
protecting [+],
privacy [+],
practice [+],
port [+],
pointer [+],
pocket pc [+],
pocket [+],
picture [+],
physical security [+],
physical [+],
philippe biondi [+],
pgp [+],
petkov [+],
peter eckersley [+],
perspectives [+],
person [+],
pending [+],
paul wouters [+],
paul vincent sabanal [+],
paul vincent [+],
paul syverson [+],
paul simmonds [+],
patrick chambet [+],
paris [+],
p security [+],
p file [+],
p event [+],
optional [+],
openhack [+],
open source system [+],
omg wtf pdf [+],
omg wtf [+],
ofir [+],
o connor [+],
not [+],
networks project [+],
networked [+],
nessus project [+],
nessus [+],
nematodes [+],
neel mehta [+],
neal krawetz [+],
navigate [+],
mosdef [+],
moore tags [+],
moore production [+],
moniz [+],
mobile devices [+],
milkymist [+],
mike shaver [+],
mike schiffman [+],
mike lynn robert baird [+],
middle [+],
messenger [+],
messaging [+],
maynor [+],
maximiliano caceres [+],
matrixay [+],
martin roesch [+],
martin khoo [+],
mark goudie [+],
mark dowd [+],
marco valleri [+],
marc schoenefeld [+],
mandy andress [+],
man [+],
maliha [+],
luiz eduardo tags [+],
lua [+],
lotus domino [+],
lotus [+],
lord [+],
locking [+],
linux event [+],
linux [+],
law [+],
lan security [+],
kris [+],
kirschbaum [+],
kernel windows [+],
kenneth geers [+],
kendall [+],
keith jones rohyt [+],
katarzyna szymielewicz [+],
k security [+],
justin ferguson tags [+],
justin ferguson [+],
julia wolf tags [+],
joy [+],
josh daymont [+],
jose nazario [+],
jose [+],
jonathan wilkins [+],
jonathan squire [+],
jonathan afek [+],
jon callas [+],
johnny cache [+],
john tan [+],
john mcdonald [+],
john curran [+],
joe damato [+],
joanna rutkowska [+],
jim harrison tags [+],
jim harrison [+],
jim edwards [+],
jericho [+],
jeremy rauch [+],
jeremy brown tags [+],
jeremy brown [+],
jaya baloo [+],
java card [+],
java [+],
japan [+],
jamie butler [+],
james shewmaker [+],
jaco [+],
isgameover [+],
isa server [+],
isa [+],
ipv [+],
ips [+],
internet worms [+],
internet applications [+],
internet [+],
international computer [+],
instrumented [+],
insider [+],
insecurity [+],
information intelligence [+],
industry authors [+],
industry [+],
ilja [+],
ike test [+],
ike event [+],
identifying [+],
icmp [+],
ian amit tags [+],
hooking [+],
honeynet project [+],
honeynet [+],
hintz [+],
himanshu dwivedi [+],
hideaki [+],
hide [+],
heffner [+],
hat [+],
harry [+],
hardware hacking [+],
hardening [+],
hard [+],
hap hazard [+],
hacks [+],
hackproofing [+],
hacking mac [+],
hack [+],
h.d. moore val [+],
gunter ollmann [+],
greg conti [+],
greetz [+],
government [+],
geers [+],
garry pejski [+],
future of internet [+],
function [+],
front [+],
francisco amato [+],
framework [+],
field [+],
fanboys [+],
fan tags [+],
fabrice desclaux [+],
exploitation [+],
experiment [+],
execution [+],
evilgrade [+],
european [+],
erik birkholz [+],
epassports [+],
enforcer [+],
effort [+],
eeye [+],
eckersley [+],
drivers [+],
dpa [+],
douchebag [+],
door [+],
domino servers [+],
dnssec [+],
dnsbernoober [+],
dns [+],
dmca [+],
distribution [+],
disclosure law [+],
dilemma [+],
diana kelly [+],
diana [+],
device drivers [+],
device [+],
design patterns [+],
design [+],
derek soeder [+],
deploying [+],
degrees [+],
def [+],
debra littlejohn [+],
dead [+],
daymont [+],
david maynor [+],
david blight [+],
dave cole saumil [+],
darrin [+],
dangling pointer [+],
dangling [+],
dan moniz [+],
cybercrime [+],
cyber threats [+],
cyber crime [+],
cryptography [+],
cryptographic authentication [+],
crime authors [+],
craig heffner [+],
craig [+],
cowbird [+],
covering [+],
convery [+],
con [+],
computing [+],
computer crime laws [+],
computer [+],
command [+],
collin mulliner [+],
clinton mugge [+],
client side [+],
cisco security [+],
cisco ios [+],
cisco infrastructure [+],
chuck willis tags [+],
chuck willis [+],
christian klein [+],
chris paget [+],
chip [+],
cell phone users [+],
card [+],
capitalism [+],
cache tags [+],
c applications [+],
building [+],
buffer overflow [+],
brussels [+],
brett moore [+],
brendan oconnor [+],
bram cohen [+],
boss [+],
bootroot [+],
blitzableiter [+],
blackout [+],
birkholz [+],
biondi [+],
biometrics [+],
billy hoffman [+],
bgp [+],
belani [+],
beginners [+],
barroso [+],
barnaby jack tags [+],
baloo [+],
badges [+],
badge [+],
automated [+],
auditing [+],
attacktecs [+],
attacker [+],
asps [+],
architecture [+],
architectural [+],
anyone [+],
andrew hintz [+],
amit [+],
ambitious undertakings [+],
alfredo andres david barroso [+],
alfredo [+],
alexander tereshkin [+],
alexander kornbrust [+],
aldora louw [+],
alberto ornaghi [+],
afek [+],
adware [+],
aaron newman [+],
Tools [+],
Skype [+],
Release [+],
Pentesting [+],
Issues [+],
Countermeasures [+],
ARM [+],
security [+],
black hat [+],
video [+],
privacy event [+],
audio [+],
security authors [+],
security event [+],
yourself,
yeoh,
x 509,
works,
with,
wireshark,
web web,
web security,
web authors,
warszawa,
walsh tags,
visual studio 2005,
virtual machine,
virtual,
video security,
vaughn tags,
val,
upgrade,
updates,
unmasking,
underground economy,
underground,
types,
training simulation,
traces,
trace,
tomasz,
textbook authors,
textbook,
temporal,
technology,
tcpdump,
tavis ormandy,
talk,
strom carlson,
strom,
stopping,
stop,
static analysis tool,
speaker max kelly,
solveable,
soldering gun,
soldering,
smartphones,
smartcard,
smart card,
slow,
sle,
simulation applications,
simulation,
shuzo,
shellcodes,
session,
sensor networks,
sensor,
security risks,
security network,
security consulting,
sebastian fernandez,
seattle wireless,
seattle,
scada systems,
saumil,
satellite event,
satellite environment,
satellite,
sandro,
san,
sai emrys tags,
ryan upton,
ryan sherstobitoff,
ryan anderson tags,
ryan anderson,
russ mcree,
rtl,
rsnake,
rook,
rodney thayer,
robert lentz,
robert jason,
robert,
rob degulielmo,
rfidiots,
restroom,
response,
reconstructing,
raynal,
raoul chiesa,
randal,
quist,
pwnage,
psychotronica,
prototype,
protocols,
privilege,
power,
point,
pki,
phishing,
philippe langlois,
perspective,
personal freedom,
pdf,
paul theriault,
paul sebastian ziegler,
paul sebastian,
paul henry tags,
paul henry,
patching,
osx,
os x,
officer,
oded,
observations,
obfuscator,
obfuscation,
noah brickman,
nkill,
nitesh,
nick depetrillo,
nicholas arvanitis,
new language,
network surveillance,
mobile phone users,
military,
mike cooper tags,
mike cooper,
mike bailey,
michael ligh,
michael kemp,
metapost exploitation,
metapost,
metaphish,
met,
memory,
max kelly,
matthew richard tags,
matthew richard,
matt krick,
mary yeoh,
mario heiderich,
mariano graziano,
marco bonetti,
management event,
malicious,
malaysia,
machine authors,
machine,
lock,
linn,
ligh,
leonardo nve,
latest trends,
language creation,
language,
langlois,
kung fu,
kung,
krick,
krakow,
kiosk,
kibler,
keynote speaker,
keynote,
kevin nassery,
keunote,
kerb,
kenneth scott tags,
kenneth scott,
ken caruso,
kelly walsh,
kelly,
karmetasploit,
joshua,
jonathan rom,
jon r. kibler,
john viega,
john benson,
joe klein,
jinx,
jesse burns,
jeroen,
jailbreaking,
jack daniel tags,
jack daniel,
jabra,
interoperability,
internet via satellite,
intelligent,
insecurities,
incident response,
incident,
immerman,
hungry,
hell,
hashes,
hansen,
hack in the box,
gun,
graziano,
goncalves,
girlfriend,
ghosting,
gcc,
gauci,
ganesh,
fuzzing,
fun,
fred von lohmann,
freakshow,
frank rieger,
frank breedijk,
feet,
failure,
facebook way,
exposition,
exploit,
evasion,
establishing trust,
escalation,
erik berls,
environment,
emmanuel gadaix,
emmanuel,
edward bachelder,
ed skoudis,
economy,
dumber,
dubai,
donation,
don ankney,
dom exploiting,
dod,
disclosure,
diplomatic security,
digital,
diane barrett,
delivery,
definitions,
decompilers,
debugging,
death,
dd wrt,
dcflux,
day,
david weston tags,
david weston,
david rook,
david mortman,
david kerb,
david byrne tags,
david byrne,
danny quist,
dalvik,
csrf,
cross domain,
crm,
crawling,
covert channel,
covert,
consulting,
conlanging,
confidence,
conficker,
con kung ,
colin ames,
cloud,
closing,
clobbering,
cisco,
chris wysopal,
chris evans,
chief security officer,
chief security,
charles edge,
caruso,
cache,
burns,
bruno goncalves,
bruce schneier,
brian wilson ryan linn tags,
brian wilson,
brian blankership,
brent baldwin robert jason tags,
boston,
bitton,
bit,
baldwin,
bad guys,
backdoors,
bachelder,
authentication,
aurora,
apps,
anti,
anthony zboralski,
ankney,
andrew immerman,
andrea cugliari,
analysis,
amplification,
alexey,
alex perry tags,
alex perry,
alek amrani,
adam savage,
adam laurie tags,
adam laurie,
abraham tags,
Software,
IPv6,
Hardware,
General
-
-
21:34
»
SecDocs
Authors:
Sébastien Bourdeauducq Tags:
embedded microcontroller Event:
Chaos Communication Camp 2011 Abstract: Milkymist develops a comprehensive solution for the live synthesis of interactive visual effects. It features one of the first open source system-on-chip designs. This talk gives a roundup of what has happened during the last 1.5 year in this project. The Milkymist project is an informal organization of people and companies who develop, manufacture and sell a comprehensive open source hardware and software solution for the live synthesis of interactive visual effects for VJs. The project goes great lengths to apply the open source principles at every level possible, and is best known for the Milkymist system-on-chip (SoC) which is among the first commercialized system-on-chip designs with free HDL source code. As a result, several Milkymist components have been reused in applications unrelated to video synthesis. For example, NASA's Communication Navigation and Networking Reconfigurable Testbed (CoNNeCT) experiment uses the memory controller that was originally developed for the Milkymist system-on-chip and published under the GNU GPL. A lot has happened since the introduction to the project at the 26C3. We have designed and are now producing and selling our own hardware called Milkymist One. The system-on-chip design has reached a very usable state, with improved graphics acceleration capabilities, support for all the interfaces on the Milkymist One (e.g. video digitizer, USB, Ethernet, MIDI, DMX, ...) and a GDB-compatible in-system debugger. On the software side, we have ported the RTEMS real time operating system and up-leveled the Linux port. We also have developed our own end-user video synthesis application which runs on RTEMS and uses the MTK embedded GUI toolkit (based on Genode FX). Several third-party applications and many libraries were successfully run on the Milkymist SoC, such as the MuPDF document viewer and the Lua and Ruby programming languagues. The SoC software can also be run and debugged in the latest versions of the QEMU emulator. This talk presents all this, and more. Demonstrations included.
-
-
2:48
»
SecDocs
Authors:
Walter van Holst Tags:
law privacy data retention Event:
Chaos Communication Camp 2011 Abstract: Right now the European Union is in a bit of a lawmaking frenzy on areas that are relevant to the internet in general. This Commission has several ambitious undertakings going on with regard to: enforcement of so-called intellectual property rights data protection data retention directive Passenger Name Records (PNR) Furthermore, several recent efforts are wrapping up and are moving to the national level, such as ACTA and webfilters against child pornography. During this lecture Katarzyna Szymielewicz (Panoptykon Foundation Poland) and Walter van Holst (European Digital Rights) will explain the main topics in Brussels, what you can do to get involved to defend your freedoms.
-
-
12:36
»
SecDocs
Authors:
Daniel Domscheit-Berg Tags:
information operation privacy Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Due to popular demand, the talk will give an introduction to the OpenLeaks system and the idea behind it.
-
12:02
»
SecDocs
Authors:
Daniel Domscheit-Berg Tags:
information operation privacy Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Due to popular demand, the talk will give an introduction to the OpenLeaks system and the idea behind it.
-
-
22:30
»
SecDocs
Authors:
Jacob Appelbaum Roger Dingledine Tags:
Tor privacy Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: Iran blocked Tor handshakes using Deep Packet Inspection (DPI) in January 2011 and September 2011. Bluecoat tested out a Tor handshake filter in Syria in June 2011. China has been harvesting and blocking IP addresses for both public Tor relays and private Tor bridges for years. Roger Dingledine and Jacob Appelbaum will talk about how exactly these governments are doing the blocking, both in terms of what signatures they filter in Tor (and how we've gotten around the blocking in each case), and what technologies they use to deploy the filters -- including the use of Western technology to operate the surveillance and censorship infrastructure in Tunisia (Smartfilter), Syria (Bluecoat), and other countries. We'll cover what we've learned about the mindset of the censor operators (who in many cases don't want to block Tor because they use it!), and how we can measure and track the wide-scale censorship in these countries. Last, we'll explain Tor's development plans to get ahead of the address harvesting and handshake DPI arms races.
-
-
22:40
»
SecDocs
Authors:
Jacob Appelbaum Roger Dingledine Tags:
Tor privacy Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: Iran blocked Tor handshakes using Deep Packet Inspection (DPI) in January 2011 and September 2011. Bluecoat tested out a Tor handshake filter in Syria in June 2011. China has been harvesting and blocking IP addresses for both public Tor relays and private Tor bridges for years. Roger Dingledine and Jacob Appelbaum will talk about how exactly these governments are doing the blocking, both in terms of what signatures they filter in Tor (and how we've gotten around the blocking in each case), and what technologies they use to deploy the filters -- including the use of Western technology to operate the surveillance and censorship infrastructure in Tunisia (Smartfilter), Syria (Bluecoat), and other countries. We'll cover what we've learned about the mindset of the censor operators (who in many cases don't want to block Tor because they use it!), and how we can measure and track the wide-scale censorship in these countries. Last, we'll explain Tor's development plans to get ahead of the address harvesting and handshake DPI arms races.
-
-
21:41
»
SecDocs
Authors:
Karsten Nohl Luca Melette Tags:
GSM phone Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: Cell phone users face an increasing frequency and depth of privacy intruding attacks. Defense knowledge has not scaled at the same speed as attack capabilities. This talk intends to revert this imbalance. Most severe attack vectors on mobile phones are due to an outdated technology base that lacks strong cryptographic authentication or confidentiality. Given this discrepancy between protection need and reality, a number of countermeasures were developed for networks and phones to better protect their users. We explain the most important measures and track their deployment. Furthermore, we will release tools to measure the level of vulnerability of networks. Sharing the results of these measurements will hopefully create problem awareness and demand for more security by phone users around the world.
-
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
-
21:41
»
SecDocs
-
-
21:51
»
SecDocs
-
-
21:52
»
SecDocs
-
13:43
»
SecDocs
-
13:43
»
SecDocs
-
-
21:49
»
SecDocs
-
21:49
»
SecDocs
-
13:49
»
SecDocs
-
-
13:17
»
SecDocs
-
-
21:45
»
SecDocs
-
-
21:48
»
SecDocs
-
21:48
»
SecDocs
-
-
21:32
»
SecDocs
-
-
21:49
»
SecDocs
-
-
12:20
»
SecDocs
-
12:20
»
SecDocs
-
-
13:45
»
SecDocs
-
-
21:34
»
SecDocs
-
21:34
»
SecDocs
-
-
21:34
»
SecDocs
-
-
21:47
»
SecDocs
-
-
21:28
»
SecDocs
-
11:39
»
SecDocs
-
-
21:49
»
SecDocs
-
4:08
»
SecDocs
-
-
10:56
»
SecDocs
-
-
21:38
»
SecDocs
-
-
21:35
»
SecDocs
-
-
21:46
»
SecDocs
-
21:46
»
SecDocs
-
-
15:13
»
SecDocs
-
-
21:53
»
SecDocs
-
-
21:38
»
SecDocs
-
21:38
»
SecDocs
-
12:39
»
SecDocs
-
-
21:34
»
SecDocs
-
21:34
»
SecDocs
-
-
21:41
»
SecDocs
-
3:59
»
SecDocs
-
-
21:28
»
SecDocs
-
-
21:53
»
SecDocs
-
21:53
»
SecDocs
-
-
21:36
»
SecDocs
-
-
21:42
»
SecDocs
-
14:32
»
SecDocs
-
5:43
»
SecDocs
-
2:05
»
SecDocs
-
-
11:21
»
SecDocs
-
-
21:30
»
SecDocs
-
-
6:46
»
SecDocs
-
-
3:22
»
SecDocs
-
-
21:45
»
SecDocs
-
-
21:41
»
SecDocs
-
-
21:28
»
SecDocs
-
21:28
»
SecDocs
-
21:28
»
SecDocs
-
21:28
»
SecDocs
-
-
12:32
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:29
»
SecDocs
-
21:29
»
SecDocs
-
12:06
»
SecDocs
-
-
21:51
»
SecDocs
-
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
-
21:44
»
SecDocs
-
-
21:38
»
SecDocs
-
21:38
»
SecDocs
-
-
21:48
»
SecDocs
-
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
-
21:44
»
SecDocs
-
21:44
»
SecDocs
-
-
21:35
»
SecDocs
-
21:35
»
SecDocs
-
21:35
»
SecDocs
-
21:35
»
SecDocs
-
-
21:31
»
SecDocs
-
21:31
»
SecDocs
-
21:31
»
SecDocs
-
11:30
»
SecDocs
-
-
21:50
»
SecDocs
-
21:50
»
SecDocs
-
-
21:42
»
SecDocs
-
21:42
»
SecDocs
-
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
21:47
»
SecDocs
-
-
21:52
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:43
»
SecDocs
-
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
-
21:30
»
SecDocs
-
21:30
»
SecDocs
-
-
22:44
»
SecDocs
-
22:44
»
SecDocs
-
22:44
»
SecDocs
-
-
22:51
»
SecDocs
-
-
22:43
»
SecDocs
-
22:43
»
SecDocs
-
-
22:52
»
SecDocs
-
-
22:48
»
SecDocs
-
22:48
»
SecDocs
-
-
22:54
»
SecDocs
-
10:53
»
SecDocs
-
-
2:18
»
SecDocs
-
2:18
»
SecDocs
-
-
3:25
»
SecDocs
-
-
0:10
»
SecDocs
-
-
3:30
»
SecDocs
-
3:30
»
SecDocs
-
-
0:46
»
SecDocs
-
0:46
»
SecDocs
-
-
2:37
»
SecDocs
-
2:37
»
SecDocs
-
2:37
»
SecDocs
-
-
5:16
»
SecDocs
-
5:16
»
SecDocs
-
-
23:54
»
SecDocs
-
23:54
»
SecDocs
-
-
3:15
»
SecDocs
-
3:15
»
SecDocs
-
-
5:56
»
SecDocs
-
-
1:01
»
SecDocs
-
-
10:35
»
SecDocs
-
10:35
»
SecDocs
-
10:35
»
SecDocs
-
10:35
»
SecDocs
-
-
1:04
»
SecDocs
-
1:04
»
SecDocs
-
-
2:23
»
SecDocs
-
2:23
»
SecDocs
-
-
2:15
»
SecDocs
-
-
2:15
»
SecDocs
-
-
23:12
»
SecDocs
-
1:48
»
SecDocs
-
-
5:14
»
SecDocs
-
-
13:01
»
SecDocs
-
-
23:20
»
SecDocs
-
1:52
»
SecDocs
-
1:52
»
SecDocs
-
-
4:49
»
SecDocs
-
-
11:11
»
SecDocs
-
-
13:16
»
SecDocs
-
11:23
»
SecDocs
-
-
13:33
»
SecDocs
Authors:
Shreeraj Shah Tags:
AJAX XSS Rich Internet Applications Event:
Black Hat USA 2010 Abstract: Web 2.0 applications are using dynamic DOM manipulations extensively for presenting JSON or XML streams in the browser. These DOM calls mixed with XMLHttpRequest (XHR) object are part of client side logic written in JavaScript or part of any other client side technology be it Flash or Silverlight. DOM driven XSS is a sleeping giant in the application code and it can be exploited by an attacker to gain access to the end user’s browser/desktop. This can become a root cause of following set of interesting vulnerabilities – Cross Widget Sniffing, RSS feed reader exploitation, XHR response stealing, Mashup hacking, Malicious code injection, Spreading Worm etc. This set of vulnerability needs innovative way of scanning the application and corresponding methodology needs to be tweaked. We have seen DOM driven XSS exploited in various different popular portals to spread worm or virus. This is a significant threat on the rise and should be mitigated by validating un-trusted content poisoning Ajax or Flash routines. DOM driven XSS, Cross Domain Bypass and CSRF can cause a deadly cocktail to exploit Web 2.0 applications across Internet. This presentation will be covering following important issues and concepts.
-
13:33
»
SecDocs
Authors:
Shreeraj Shah Tags:
AJAX XSS Rich Internet Applications Event:
Black Hat USA 2010 Abstract: Web 2.0 applications are using dynamic DOM manipulations extensively for presenting JSON or XML streams in the browser. These DOM calls mixed with XMLHttpRequest (XHR) object are part of client side logic written in JavaScript or part of any other client side technology be it Flash or Silverlight. DOM driven XSS is a sleeping giant in the application code and it can be exploited by an attacker to gain access to the end user’s browser/desktop. This can become a root cause of following set of interesting vulnerabilities – Cross Widget Sniffing, RSS feed reader exploitation, XHR response stealing, Mashup hacking, Malicious code injection, Spreading Worm etc. This set of vulnerability needs innovative way of scanning the application and corresponding methodology needs to be tweaked. We have seen DOM driven XSS exploited in various different popular portals to spread worm or virus. This is a significant threat on the rise and should be mitigated by validating un-trusted content poisoning Ajax or Flash routines. DOM driven XSS, Cross Domain Bypass and CSRF can cause a deadly cocktail to exploit Web 2.0 applications across Internet. This presentation will be covering following important issues and concepts.
-
13:27
»
SecDocs
Authors:
Thomas Ryan Tags:
social engineering Event:
Black Hat USA 2010 Abstract: Given the vast number of security breaches via the internet, the experiment seeks to exploit the fundamental levels of information leakage—the outflow of information as a result of people’s hap-hazard and unquestioned trust. The experiment was conducted by creating a blatantly false identity and enrolling on various social networking websites. By joining networks, registering on mailing lists, and listing false credentials, the conditions were then set to research people’s decisions to trust and share information with the false identity. The main factors observed were: the exploitation of trust based on gender, occupation, education/credentials, and friends (connections). By the end of this Experiment, Robin finished the month having accumulated 100’s connections through various social networking sites. Contacts included executives at government entities such as the NSA, DOD and Military Intelligence groups. Other friends came from Global 500 corporations. Throughout the experiment Robin was offered gifts, government and corporate jobs, and options to speak at a variety of security conferences. Through this 28 day experiment, it became evident that the propagation of a false identity via social networking websites is rampant and viral. Much of the information revealed to Robin Sage violated OPSEC procedures. The deliberate choice of an attractive young female exposed the role that sex and appearance plays in trust and people’s eagerness to connect with someone. In conjunction with her look, Robin Sage’s credentials listed on her profile resulted in selection perception; people’s tendency to draw unwarranted conclusions in their attempt to make a quick decision. By acquiring a large number of connections, Robin had the ability to identify the individual who was positioned to provide the most intelligence based on their involvement in multiple government agencies. The false identity combined with carefully chosen false credentials led to a false trust that could have resulted in the breach of multiple security protocols.
-
-
12:03
»
SecDocs
Authors:
Francis Brown Rob Ragan Tags:
intelligence Event:
Black Hat USA 2010 Abstract: During World War II the CIA created a special information intelligence unit to exploit information gathered from openly available sources. One classic example of the team’s resourcefulness was the ability to determine whether Allied forces had successfully bombed bridges leading into Paris based on increasing orange prices. Since then OSINT sources have surged in number and diversity, but none can compare to the wealth of information provided by the Internet. Attackers have been clever enough in the past to take advantage of search engines to filter this information to identify vulnerabilities. However, current search hacking techniques have been stymied by search provider efforts to curb this type of behavior. Not anymore - our demonstration-heavy presentation picks up the subtle art of search engine hacking at the current state and discusses why these techniques fail. We will then reveal several new search engine hacking techniques that have resulted in remarkable breakthroughs against both Google and Bing. Come ready to engage with us as we release two new tools, GoogleDiggity and BingDiggity, which take full advantage of the new hacking techniques. We’ll also be releasing the first ever “live vulnerability feed”, which will quickly become the new standard on how to detect and protect yourself against these types of attacks. This presentation will change the way you've previously thought about search engine hacking, so put on your helmets. We don't want a mess when we blow your minds.
-
-
0:18
»
SecDocs
Authors:
Christoph Weber Tags:
router exploiting Cisco Event:
Hashdays 2010 Abstract: The talk demonstrates, based on Cisco devices, that DDoS attacks, spam and viruses are not only coming from the "normal suspects" (PC, server and mobile devices). There are other devices, like routers or switches, which can do the same. All these devices are becoming more and more "intelligent" and have "features", which will make it possible to realize all kinds of attacks. Because of broad distribution of all these feature packed devices to the customer, these devices have a greater potential for misuse and will in the future become more in focus of hackers.
-
0:18
»
SecDocs
Authors:
Christoph Weber Tags:
router exploiting Cisco Event:
Hashdays 2010 Abstract: The talk demonstrates, based on Cisco devices, that DDoS attacks, spam and viruses are not only coming from the "normal suspects" (PC, server and mobile devices). There are other devices, like routers or switches, which can do the same. All these devices are becoming more and more "intelligent" and have "features", which will make it possible to realize all kinds of attacks. Because of broad distribution of all these feature packed devices to the customer, these devices have a greater potential for misuse and will in the future become more in focus of hackers.
-
-
16:14
»
SecDocs
-
-
11:34
»
SecDocs
-
11:34
»
SecDocs
-
-
14:36
»
SecDocs
-
14:35
»
SecDocs
-
-
14:58
»
SecDocs
-
11:25
»
SecDocs
-
11:24
»
SecDocs
-
-
11:35
»
SecDocs
-
11:34
»
SecDocs
-
-
12:16
»
SecDocs
-
12:16
»
SecDocs
-
-
14:23
»
SecDocs
-
-
12:52
»
SecDocs
-
-
14:33
»
SecDocs
-
13:43
»
SecDocs
-
13:43
»
SecDocs
-
-
5:30
»
SecDocs
-
5:29
»
SecDocs
-
-
13:16
»
SecDocs
-
13:15
»
SecDocs
-
-
11:34
»
SecDocs
-
-
9:12
»
SecDocs
-
9:09
»
SecDocs
-
-
10:10
»
SecDocs
-
10:10
»
SecDocs
-
-
15:17
»
SecDocs
-
-
14:29
»
SecDocs
-
-
13:55
»
SecDocs
-
12:55
»
SecDocs
-
-
13:36
»
SecDocs
-
-
11:35
»
SecDocs
-
-
11:01
»
SecDocs
-
-
11:38
»
SecDocs
-
-
13:23
»
SecDocs
-
-
12:00
»
SecDocs
-
-
11:20
»
SecDocs
-
-
11:27
»
SecDocs
-
-
2:49
»
SecDocs
-
2:39
»
SecDocs
-
2:37
»
SecDocs
-
-
22:25
»
SecDocs
-
22:25
»
SecDocs
-
22:25
»
SecDocs
-
22:25
»
SecDocs
-
-
1:56
»
SecDocs
-
1:39
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
3:37
»
SecDocs
-
3:25
»
SecDocs
-
3:08
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
Authors:
John Curran Tags:
IPv6 Event:
DEFCON 18
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
12:52
»
SecDocs
-
11:32
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:47
»
SecDocs
-
21:38
»
SecDocs
-
-
8:43
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
11:39
»
SecDocs
-
-
2:21
»
SecDocs
Authors:
Julia Wolf Tags:
PDF Event:
SecTor 2010