Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
EH-Net
Calendar Of Events
BSidesDelaware 2010
EH-Net
May 25, 2013, 01:28:05 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
Calendar Of Events
(Moderator:
don
) >
BSidesDelaware 2010
Linked Events
BSidesDelaware 2010
: November 06, 2010
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: BSidesDelaware 2010 (Read 6660 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4169
Editor-In-Chief
BSidesDelaware 2010
«
on:
September 02, 2010, 09:28:55 PM »
BSidesDelaware 2010
November 6, 2010
New Castle, DE
Didn't get enough at #BSidesLasVegas? Didn't get to go? Didn't get to speak? Don't know what it is? If you're from the east coast and not flying to Texas for BSidesDFW you now have plans.
Cost: Free (as always!)
Venue
Wilmington University, New Castle Campus
320 N. DuPont Highway
New Castle, DE 19720-6491
For more info:
http://www.securitybsides.com/BSidesDelaware
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Ketchup
Hero Member
Offline
Posts: 1021
Re: BSidesDelaware 2010
«
Reply #1 on:
September 03, 2010, 06:18:26 AM »
Hmm, this is close to me. Anyone else thinking about going to this one?
Logged
~~~~~~~~~~~~~~
Ketchup
3xban
Hero Member
Offline
Posts: 608
Re: BSidesDelaware 2010
«
Reply #2 on:
October 25, 2010, 09:24:43 AM »
I'm registered for this and coming in from CT. This will be my first one.
Logged
Certs: GCWN
(@)Dewser
Agoonie
Full Member
Offline
Posts: 177
Re: BSidesDelaware 2010
«
Reply #3 on:
November 06, 2010, 06:35:06 PM »
Just came back from it. It was very cool, loved the info on Shodan, ShoNuff and Lockpicking.
Logged
OSCE, OSCP, OSWP, CISSP, GPEN
www.agoonie.com
chrisj
Hero Member
Offline
Posts: 1163
Re: BSidesDelaware 2010
«
Reply #4 on:
November 08, 2010, 09:44:55 AM »
Could someone do a write up of it, let us know as much as you can in 1000 or so words?
Logged
OSWP, Sec+
Agoonie
Full Member
Offline
Posts: 177
Re: BSidesDelaware 2010
«
Reply #5 on:
November 08, 2010, 09:12:40 PM »
Unfortunately, I arrived late to the Security B-Sides Delaware conference, to my first conference no less. Long story. Anyway, it was great to see so many smart people presenting information. They had two conference rooms and a main auditorium. Some of the presenters were Jason Ross, Marcus Carey, Dave Marcus, Scott Hazel, Michael “theprez98” Schearer and “Grecs”. For those who could not attend, they have been posting video of the conference online. I saw a couple of people tweet (hxxp://www.ustream.tv/channel/security-bsides-delaware-track-1), (hxxp://www.ustream.tv/channel/security-bsides-delaware-track2) and (hxxp://www.vimeo.com/16585113).
The four talks I got to see were Lockpicking, Pwn an ISP in 10 Minutes, Intro to ShoNuff and Social Engineering for Non-Penetration Testers. I have always thought about how important it is to have physical security and the lockpicking class proved it. Dr. Robert Tran spoke on the basic locks such as tumblers and wafers and how to unlock them. It should not be that simple to unlock these. If you guys are curious, his group’s site is (hxxp://toool.us). You can actually buy tool sets on their site. Very cool. He used rakers, half diamond, and hook tools. You see it on TV all the time, but it was incredible to see it in person. He explained it is all about light pressure. Oh, and before I forget two rules: don’t try to pick a lock that you don’t own and don’t pick a lock that you rely on! I am glad he said that, I was ready to try to lockpick my front door the minute I could. It would really suck to have to replace my door lock because I got overzealous. =-)
Next, SHODAN!! The speaker was “theprez98” and he talked about the Shodan Search Engine (hxxp://www.shodanhq.com). It is not your Google search engine. It gives info such as the IP address, hostname, port numbers, and OS versions of devices on the Internet. It is very powerful. He did a demonstration of how easily you can search for a Cisco device that has no protection and allows “level 15” permission over the device. It was scary stuff and definitely worth a look of his video.
Next up, ShoNuff! We didn’t get to see a demonstration of ShoNuff due to some technical difficulties but Jason Ross still gave us the overview of it. The site is (hxxp://whoisthemaster.org:8080/). It basically does a super WHOIS of an organization. It provides the network IP address range of the company and even ties to Shodan using the new API of Shodan. It seems to me it is invaluable when you are doing passive recon work for a penetration test. It is amazing that this started from curiosity and the scarcity of the IPv4 addresses available.
Lastly, I sat in on the social engineering demonstration by Scott Hazel. He basically answered the question, “How do I practice social engineering when I am not doing a penetration test and I don’t want to get shot?” It is a very good question. I mean how do you get skills on social engineering so that you can be asked to do a penetration test? He gave some answers I would not have thought of such as watching TV shows on mute just so you can read nonverbal communication. It makes sense right and it is simple. Also, try listening! Again, sounds simple but how many of us actually do it. You can start by just listening to your wife, girlfriend, kids, friends and co-workers. You will score points with the wife/gf at least. =-). Finally, to get to that “layer 8” connection is to talk to people. Just converse with strangers and see how much you can learn about people. He gave some anecdotal examples when he described that you should be “the fail”. It was hilarious. Basically, you can get loads of information from people simple by stating things that are incorrect. Someone will always be there to try to correct you with information that they should be give.
I think the conference was a success. It was informative, exciting and inspiring. I would definitely recommend looking at their videos if you could not attend. I am hoping this is the start of more great conferences to come.
Logged
OSCE, OSCP, OSWP, CISSP, GPEN
www.agoonie.com
chrisj
Hero Member
Offline
Posts: 1163
Re: BSidesDelaware 2010
«
Reply #6 on:
November 09, 2010, 10:57:27 AM »
That's awesome. Thanks.
If you haven't gotten it yet, pick up Deviant's book. Really worth reading.
You should hit up their site / forum (forum.toool.us) to see if there is one in your area if you want to learn more about locks.
Logged
OSWP, Sec+
3xban
Hero Member
Offline
Posts: 608
Re: BSidesDelaware 2010
«
Reply #7 on:
November 12, 2010, 09:08:39 PM »
Good recap killjoy! It was a great time, I can't wait for the next one and hope it is up my way, that 4 hour drive was rough!
But sooo worth it!!
It was tough trying to pick the talks.
Logged
Certs: GCWN
(@)Dewser
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
/root
: Fashion Advice Anyone Can Follow And Look Great
(0) by
storenoh63
Gates
: How To Prevent Injuries In Actively Playing Volleyball
(0) by
storenoh63
Skillz
: How To Find Gifts That Are Not Tacky Or Cheesy
(0) by
storenoh63
Ethical Hacktivism
: Lia Sophia Jewelry A Multilevel Marketing Company
(0) by
storenoh63
News Items and General Discussion About EH-Net
: Victorias Secret Price Of Buy Wholesale
(0) by
storenoh63
Tutorials
: Pasha Jewelry Offers Elegance At Reasonable Prices
(0) by
storenoh63
J. Peltier
: Amrapali Dream Valley High Rise Residential Villas At Noida Extension
(0) by
storenoh63
Skillz
: Get Paid To Write Online - Right Now Is A Great Time To Make Money Writing!
(0) by
storenoh63
Hoffman
: Infant Bracelets San Pedro California
(0) by
storenoh63
Cyber Warfare
: How Reliable Is Pay-per-click Advertising
(0) by
storenoh63
CWNP Certs
: Hobby classes - for improving physical as well as mental health
(0) by
storenoh63
Mass Media
: Sass And Class Why High Heel Shoes Are Here To Stay
(0) by
storenoh63
OSCP - Offensive Security Certified Professional
: Reasons Why You Should Buy Bmw
(0) by
storenoh63
Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
: Enema Supplies
(0) by
storenoh63
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.