Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow EH-Netarrow Calendar Of Eventsarrow CanSecWest 2008
Ethical Hacker Community Forums
December 03, 2008, 12:03:52 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Linked Events
  • CanSecWest 2008: March 26, 2008 - March 28, 2008
Pages: [1]   Go Down
  Print  
Author Topic: CanSecWest 2008  (Read 3108 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: December 19, 2007, 11:52:18 AM »

CanSecWest 2008
March 26-28 2008
Mariott Renaissance Harbourside
Vancouver, British Columbia


Quote
Interact with the security community

CanSecWest, the world's most advanced conference focusing on applied digital security, is about bringing the industry luminaries together in a relaxed environment which promotes collaboration and social networking. The conference lasts for three days and features a single track of thought provoking presentations, each prepared by an experienced professional and talented educator who is at the cutting edge of his or her field. We give preference to new and innovative material, highlighting important, emergent technologies, techniques, or best industry practices.

The conference is single track, with one hour presentations over the duration beginning at 9:00 a.m. The registration fee includes the catered meals, and there will be a vendor display and lounge/eating area, where wireless internet access will be available (as well as in the speaking theater).

http://www.cansecwest.com

As always, please share your thoughts on this event and whether or not you will be attending.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 295



View Profile
« Reply #1 on: December 19, 2007, 03:30:03 PM »

Have any of you ever gone to this?  As in.. is it worth me making a 3 hour drive?
Logged

"Bad.. Good?  I'm the guy with the gun"
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #2 on: March 27, 2008, 12:32:54 AM »

Any EH-Netters in attendance this year? Would love to hear about it as would other readers. Your feedback really helps us figure out how to wisely spend our time and money.

Thanks,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #3 on: March 28, 2008, 09:24:36 PM »

Our friends at Intelguardians make a big splash at CanSecWest. Check out these stories by Dan Gooden of The Register:

Quote

Next time you go to the loo, bring your locked laptop with you
CanSecWest | DaisyDukes brings memory sniffing to the masses
By Dan Goodin • Friday 28 Mar 2008 11:02

Building off recent research that showed how to extract encryption keys from a computer's memory, a penetration testing company has unveiled a tool that sniffs out passwords, documents, and other sensitive data in a matter of minutes.

DaisyDukes is a memory sniffer that resides on a USB device. A researcher can plug it into an unattended machine that is turned on but has been locked and reboot the machine off a compact operating system contained on the drive. Depending on the user's needs, it can be configured to capture the entire contents of a computer's memory, or sniff out only certain types of data - say a password to access the company network or unlock a user's private encryption key.

It turns out both Windows and Linux retain "boatloads and boatloads" of passwords in memory, said Sherri Davidoff, a security analyst with IntelGuardians, the penetration-testing firm that developed the tool. It's already been able to isolate passwords for Thunderbird, AOL Instant Messenger, GPG, SSH, Outlook, Putty and TrueCrypt, among others, and with additional research they believe they can find many more.

"The idea here is let's see if we can hit an office building, get in and out in 25 minutes or less and walk out with some interesting passwords," said Tom Liston, an IntelGuardians security consultant who along with Davidoff co-presented the tool at the CanSecWest security conference in Vancouver.


Quote

How safe is VMware's hypervisor?
CanSecWest | The debate rages on
By Dan Goodin • Thursday 27 Mar 2008 16:03

CanSecWest VMware researcher Oded Horovitz got an earful when he told a group of security buffs his company's virtualization software was theoretically impenetrable. Speaking at the CanSecWest conference in Vancouver, his hour-long presentation, titled Virtually Secure, included a slide titled "VM Escape" that carried the following bullet point:

"Though impossible by design, the hypervisor can still have implementation vulnerabilities."

It was more than some attendees could bear.

"And the Titanic was unsinkable," Mike Poor, a senior security analyst for IntelGuardians shot back. Other attendees complained that security increasingly looked like an afterthought as VMware continued to add new bells and whistles to its Workstation and ESX Server products - many from third party companies.

"I take strong issue with your saying 'trust the hypervisor' when you're expanding it to run other people's APIs," one attendee, who asked not to be identified, told Horovitz immediately following his talk.


Well done,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
pseud0
Full Member
***
Offline Offline

Posts: 143



View Profile
« Reply #4 on: March 30, 2008, 08:25:13 AM »

The Vista laptop got Pwned...

http://dvlabs.tippingpoint.com/blog/2008/03/28/pwn-to-own-final-day-and-wrap-up

Quote
7:30pm PST Update - Vista Laptop was Won!: Congratulations to Shane Macaulay from Security Objectives - he has just won the Fujitsu U810 laptop running Vista Ultimate SP1 after it was installed with the latest version of Adobe Flash. Not only is he the official winner of the Fujitsu laptop, but also $5,000 from us. Shane received some assistance from his friends Derek Callaway (also from Security Objectives) and Alexander Sotirov. If you'll also remember, Shane Macaulay was Dino Dai Zovi's on-site team member at last year's PWN to OWN event in which they ultimately took the top prize.

The new Adobe Flash 0day vulnerability that Shane exploited has been acquired by the Zero Day Initiative, and has been responsibly disclosed to Adobe who is now working on the issue.  Until Adobe releases a patch for this issue, neither we nor the contestants will be giving out any additional information about the vulnerability.  You can track the status of the vulnerability on the Zero Day Initiative upcoming advisories page under ZDI-CAN-306. 

I was actually in the offsec IRC chatroom when this happened.  One of their guys was doing live posts from the event.
Logged

CISSP, CISM
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.042 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.