Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 11 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Gatesarrow shmoocon 08 day 2
Ethical Hacker Community Forums
October 12, 2008, 01:13:11 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: shmoocon 08 day 2  (Read 863 times)
0 Members and 1 Guest are viewing this topic.
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1008


View Profile WWW
« on: February 17, 2008, 10:10:54 PM »

Ok, i got up a little late and it took the spouse a min or two to get me to the metro, then the metro was doing work on one of the tracks, suffice to say i was late, i got there for noon talks, i tried to get a hotel room friday nite but no dice, did get on saturday nite so i didnt have to deal with the metro crap.

Day2

started with Jay Beale's They're Hacking Our Clients! Why are We Focusing Only on the Servers" talk. it didnt seem any different that the slides from toorcon. The jist is that we should incorporate client side testing into pen tests, because that's how people are getting in now and that we shouldnt allow customers to cop out and say "we have a user education program so no attacking the clients." He then went on to talk about some VA stuff like checking squid logs for clients on your network that are running vulnerable versions of apps like browsers or mail clients. You would then blackhole those guys off until patches were applied. I'll let Dean vent the most on that, because he raised the great point of if you blackhole some mucky muck's laptop and tell them to patch their box you're gonna get you ass fired up especially since its usually IT's job to patch stuff and most users dont have permissions to even update stuff most of the time.

next up was Why are Databases so Hard to Secure by Sheeri Cabral, i rolled in late and must have missed the good stuff because by the time i got in there i just saw a bunch of SQL in there and some talk about how developers should do something or the other...meh

after that was VoIP Penetration Testing: Lessons Learned by John Kindervag and Jason Ostrom for me the best talk of the day. they talked about some features they added to voiphopper. If you have seen the security focus article on VoIP hacking they just added to that. it was good though.

Got Citrix? Hack It! by Shanit Gupta talked about different ways to break out of Citrix apps to get command shells, IE boxes, or explorer boxes. pretty neat.

Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to "SPIKE Land"
by Enno Rey and Daniel Mende. I'm a big believer in listening to a few talks at a con that are above your skill level so you can rise up to that. i'm not an exploit-dev guy, i wish i was so i took the opportunity to listen to the layer 2 fuzzing talk. enno and daniel basically modifed SPIKE to fuzz layer 2 cisco protocol like DTP, VTP, MLPS and two others i dont remember. no exploitation, but they were able to get some "fun" reactions from different cisco products.

talked some way cool wireless stuff with one of the intelguardians. He showed me wi-spy and zigbee and talked about the cool things in the future that could be done against zigbee type products.

didnt make the shmoo party, had dinner with dean and talked about the talks and some other projects we got working then hung out, had beers, and talked SQLI with j0e and dean.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 23 queries.
 
Polls
Why a Career in Ethical Hacking:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.