Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Columnsarrow Gatesarrow Shmoocon Day1
EH-Net
May 19, 2013, 07:45:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Shmoocon Day1  (Read 8354 times)
0 Members and 1 Guest are viewing this topic.
LSOChris
Guest
« on: March 23, 2007, 10:43:24 PM »

Don was nice enough to sponsor me to go to Shmoocon for EH-net.

site: http://www.shmoocon.org/

so here is my wrap up for day 1:

this is the 3rd year of shmoocon and started off very well.

We started with Bruce Potter giving the crowd a warm up to the day's speakers and a bit of history about the con and another bit about how the ticket sales went.  in case you don't know, the first batch sold out in about 3 days, the second batch in 45 minutes and the last batch in 8 minutes.  Of course there i was trying to buy my ticket in that last batch and didnt make it in the first 8 minutes  Angry.  thankfully Don came to the rescue.

Here is the speaker's schedule:
http://www.shmoocon.org/schedule.html

Today's talks were 20 minute talks with 10 minutes Q&A.

H1kari
Hacking the Airwaves with FPGA's:

*this talk was about some advancements & research in WPA & WEP cracking drastically speeding up cracking time using FPGA's.  He did a couple of demos and was cracking WEP and WPA with cowpatty on windows and was on the order of 4 times faster with FPGA than without.  He also talked about some flaws in OS X FileVault and being able to crack the hashes with John The Ripper.  He also did a demo cracking bluetooth PINs, again considerably faster with the FPGA than without.  i was really wanting to go out and purchase one until he dropped the $1900.00 pricetag for one. 

Eoin Miller and Adair Collins
Auditing Cached Credentials with Cachedump:

*this talk was about using the Cachedump tool during assessment to pull down the cached administrator credentials that can be left over when a domain admin logs in to a windows box for maintenance.  they discussed that these creds can be cached when  the admin logs in locally, remotely with RDP, using the "run as" command, logging in with dameware or if admins share a laptop with other users.

they had a group policy script (dont know if they are releasing it) that would go thru using cachedump look for cached admin creds and delete the key out of the registry which should pretty much mitigate the attack.

Adam Shostack
Security Breaches are Good for You:

*This talk was about how security breaches should be good for us (as the consumer).  He talked about TJMAX and choicepoint data losses/breaches and how you would have thought that these companies would have lost major $$ and customers but it didn't seem to go that way.  fairly interesting discussion.  the major obstacles to this research seems to be the lack of reporting by companies of losses or breaches or personal data even though most states require it by law.

Johnny Long
No-Tech Hacking

*Excellent talk on really just observing things around you from a hacker's perspective.  like what people are wearing at the airport letting you know what they do for a living, security badges, DoD stickers on cars telling ALOT about the person driving, and how shoulder surfing at the airport or on a plane is still a very real threat.  He also had another good piece on how valuable dumpster diving still is.  really good talk considering it had nothing to with computers per say but still putting those hacker mind skills to work.

Deviant Ollam, Noid and Thorn
Boomstick-Fu: The Fundamentals of Physical Security at its Most Basic Level:

*this talk was about firearms. handguns versus rifles vs shotguns.  good Q&A with some ex law enforcement people.

Sergey Bratus
Simple Entropy-based heuristics for Log and Traffic Analysis:

*when the talk starts out with the guy explaining entropy and log and traffic analysis to all the people in the crowd you know you are in for some good con-fu and it was good.  Check out his speaker bio for more info:
http://www.shmoocon.org/speakers.html

Keynote Address: Aviel Rubin:

*GREAT talk on Breaking into systems; Political, Legal, & Technical Aspects.  Covered responsible disclosure and the law, how/when to involve lawyers, DMCA issues, and creating adversaries out of the the companies whose software you broke into little pieces :-)   Also good points on making sure you inform management of what you found so they can line up their lawyers for damage control if the company decides to play rough.  Dr. Rubin talked about his research into the Diebold voting machines and cracking the RFID (exxon/mobil speedpass) as well as some of the car keys that use similar technology to verify that your key is paired with your car.

His slides are already posted on his blog, so check them out:
http://avi-rubin.blogspot.com/



Other things of note were:

T-shirts were 10 bucks!  Grin

Got to meet Ed Skoudis, that was cool!

Crowd was good, location was good, and atmosphere was good too.
« Last Edit: March 23, 2007, 10:49:21 PM by ChrisG » Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #1 on: March 23, 2007, 11:00:23 PM »

Excellent! Sounds pretty good so far. Thanks for the info and post. Keep us updated Smiley
Logged
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #2 on: March 24, 2007, 09:55:13 AM »

Wow Chris Thanks!! You took some serous notes Tongue. I am not hanging at the edge of my seat for "day 2".

Keep up the good work and try to get at least 4 hours sleep Smiley

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #3 on: March 24, 2007, 10:04:13 AM »

Well done. I can't wait for Day 2!

Once again, you prove that any investment I make in you is well worth it.

Slimjim - You're next with Notacon (I'll PM you details). Chris sets the bar high, doesn't he?

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.