Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3Rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

Defcon 16 — ‘Awesome!’

p2pnet news view Freedom | P2P:- In the last century I ran OTRiCS (On the Road in CyberSpace), a personal web page (they didn’t have blogs back then) which struck a chord with one or two members of the hacking community.

Naturally, Defcon came up more than once, but it wasn’t in the context of America’s DEFense readiness CONdition (DEFCON) readiness level for the US armed forces.

Rather, it referred to DefCon, “Real Time Social Networking for Ninjas,” the world’s largest annual hacker convention launched in 1993 and held every year in Las Vegas, Nevada.

I’d love to be able to carry more posts on hackers (most of whom I greatly respect) and hacking (an art I greatly admire) but I don’t have the manpower or the resources to be able to do that.

But I’m in luck with DEFCON 16, which has just finished.

Silicon Valley programmer Danny Colligan was there. He filed briefs on what went down on chainlynx and is generously allowing us to re-run his post.

It was, “awesome, as expected,” he says, going on »»»

  • The first presentation I went to was called “Hacking in the Name of Science.” Here a bunch of University of Washington grad students and a professor discussed the sweet research they are doing, almost all of which has been in the news (Implicating ‘downloading’ printers to the RIAA monitors, RFID ghost proxies, TCP information leakage, voting machine vulnerabilities, TrueCrypt vulnerabilities, implantable medical device hacking, ISP injected ads, etc.). They discussed the difference between just hacking and what you need to do in an academic setting to study what anyone else would call hacking. They encouraged attending academic security conferences, such as ACM CCS, NDSS, IEEE Security + Privacy, HotSec and Woot
  • A talk entitled “Satan is on my Friends List” detailed the security vulnerabilities in OpenSocial-enabled websites. These guys demonstrated some hilarious things, including using a CSRF DOS attack: using an img tag placed in an html-enabled form that displays on a page, you can automatically logout anyone that sees that img by pointing the img’s src attribute to the logout page. The speakers talked about how the socnet widget applications space is essentially a security free-for-all: apps hacking personal information, apps hacking other apps, etc. An opt-in security model for javascript safety in apps exacerbates the problem. An amusing conclusion to the talk was the speakers’ impersonation of another security researcher on social networks which fooled his colleagues and family alike.
  • Locksport enthusiast Eric Schmedl gave a talk that had some amusing anecdotes about cloak-and-dagger spying. Mary Lou McFate (NRA infiltrator of anti-gun groups), reconstructing passwords from audio of keystrokes, and multiple phone bugging technologies were discussed.
  • Fyodor gave a talk on nmap, the tool he created and how he used it to scan a large subset of the Internet. He also presented some new features of the tool, including traceroute, ping, and netcat-like functionality… what can’t it do?
  • I briefly stopped in on a talk called “Taking Back Your Cellphone” which plugged the site HowardForums as an excellent resource for phone modification.
  • The activity that I took part in for a fair share of my time there was the Lockpicking Village. I bought a set of lockpicks, and tried my skills on a variety of locks lying about the room. I also listened to talks on how to crack certain types of locks, including masterlocks (use coke can shiv, patterns for figuring out combo).
  • Probably the most interesting thing that happened at DEFCON nobody got to see: a judge ordered a group of MIT students not to talk about hacking the Boston Subway system. This was rather pointless because 1) the presentation was distributed on CD before the gag was ordered 2) the ban was lifted after the conference 3) MIT’s student newspaper put the presentation up on its site
  • Other cool things: the badge, the mystery box
  • Didn’t see these presentations, but I looked at them on the CD:
    • “The Death of Cash” features a preview of a world without cash. People are turning to credit because it is more convenient, banks love it because of better profit margins, government loves it because it makes you easier to track. (Note: Illegal to transfer $10,000 in/out of the country without declaring it). This is getting worse with stupid legislation (Patriot Act). Also, national security risk: electronic outages now mean that people can’t get access to cash (even more troublesome as electric grid becomes less reliable). Strong crypto might be the basis of a future E-payment system. Advice: keep some cash on hand for emergencies, use non-cash as little as possible. thowlett@netsecuritysvcs.com says the presentation can be downloaded at www.netsecuritysvcs.com/presentations/defcon16/ but I don’t see it there…
    • An introduction to ham radio called “Ham for Hackers”
    • A presentation on Javascript obfuscation that goes over the following methods: ASCII/Unicode escapes, XOR (ASCII/encoding), string splitting, simple encryption, non-obvious variable and function names, member enumeration, whitespace encoding/decoding
    • Another presentation on SCADA systems that made me have nightmares
    • A HOWTO on SSL cookie hijacking by Tor developer Mike Perry: insert an img tag with src mail.yahoo.com into an unencrypted connection and read their cookie, then save that cookie to cookies.txt and read their email (over SSL, if you want!)
    • OCR tools: tesseract, jocr, ocrad
    • A presentation similar to “Satan is on my Friends List” for Google Gadgets

(Thanks, Danny)

.Add to Technorati Favorites .Stumble It!


Use free p2pnet newsfeeds for your site. It’s really easy!

Subscribe
to p2pnet.net
| | rss feed: http://p2pnet.net/p2p.rss | | Mobile – http://p2pnet.net/index-wml.php


Net access blocked by government restrictions? Use Psiphon from the Citizen Lab at the University of Toronto. Go here for details. Download here.

HOME

2 Responses to “Defcon 16 — ‘Awesome!’”

  1. chronoss Says:

    haha and all that knowledge ya think they could stop hackers nope. the best stuff never makes it there, nor should it, so people can steal your ideas and make money off your intelligence, its a scam the thing now is and did turn into nothing more hten corporate control.

  2. f4te Says:

    “using an img tag placed in an html-enabled form that displays on a page, you can automatically logout anyone that sees that img by pointing the img’s src attribute to the logout page. ”

    wiiicckkeedddd!!!
    does this work on fache-book? hell, im trying it now!

Leave a Reply

Please no Spam, flaming (attacking others), trolling, and posting off-topic. Thanks.

    Advertisements
TekSavvy


Remove Spyware with AntiSpyware for Windows®